Coreutils 'dir' has been reported prone to an integer overflow vulnerability. The issue reportedly presents itself when handling large integer value '-w' (width) command line arguments passed to the vulnerable application. Due to the nature of this issue it may possibly be leveraged to deny service to applications that use the 'dir' utility. It has been conjectured that when invoked by an application with a malicious integer value passed via the '-w' argument, the affected application may hang while waiting for the utility to return output.
Coreutils 'dir' has been reported prone to an integer overflow vulnerability. The issue reportedly presents itself when handling large integer value '-w' (width) command line arguments passed to the vulnerable application. Due to the nature of this issue it may possibly be leveraged to deny service to applications that use the 'dir' utility. It has been conjectured that when invoked by an application with a malicious integer value passed via the '-w' argument, the affected application may hang while waiting for the utility to return output.