Incorrect libcap_net limitation list manipulation
Vulnerability Description
In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updated constraints are strictly subsets of the active constraints. When only a list of resolvable domain names was specified without setting any other limitations, an application could submit a new list of domains including include entries not previously listed. This could permit the application to resolve domain names that were previously restricted.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-5978
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Shawn Webb
- Mariusz Zaborski
References
More from FreeBSD
View All →Affected Vendor
FreeBSD
View all reports →