GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.
CVSS Metrics