MEDIUM
Stack buffer overflow in "read_file" function
Published Jun 1, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.64%
Description
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via malformed config files. This issue affects libeconf: before 0.5.2.
Affected products
-
- Version ?StatusaffectedConstraints<0.5.2
- Version
No data.
Red Hat Enterprise Linux 9
libeconf-0:0.4.1-3.el9_2
Fixed · RHSA-2023:4347
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | libeconf-0:0.4.1-3.el9_2 | Fixed | RHSA-2023:4347 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- https://access.redhat.com/security/cve/CVE-2023-22652 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2212463 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-22652 Issue TrackingVendor Advisory
- https://github.com/openSUSE/libeconf/issues/177 exploit
- https://https://github.com/openSUSE/libeconf/issues/177 Broken Link
- https://lists.debian.org/debian-lts-announce/2025/05/msg00016.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SDD5GL5T3V5XZ3VFA4HPE6YGJ2K4HHPC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SMG5256D5I3GFA3RBAJQ2WYPJDYAIL74/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAYW7X753Z6GOJKVLQPXBDHISN6ZT233/
- https://nvd.nist.gov/vuln/detail/CVE-2023-22652
- https://www.cve.org/CVERecord?id=CVE-2023-22652
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner suse
Published Jun 1, 2023
Updated May 13, 2025
Reserved Jan 5, 2023
Link CVE-2023-22652
CISA Vulnrichment
Updated Jan 10, 2025