Stack buffer overflow in "read_file" function
Vulnerability Description
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via malformed config files. This issue affects libeconf: before 0.5.2.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-22652
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- https://github.com/yangjiageng
References
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-22652
- https://https://github.com/openSUSE/libeconf/issues/177
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SMG5256D5I3GFA3RBAJQ2WYPJDYAIL74/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SDD5GL5T3V5XZ3VFA4HPE6YGJ2K4HHPC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAYW7X753Z6GOJKVLQPXBDHISN6ZT233/
More from openSUSE
View All →Affected Vendor
openSUSE
View all reports →