Podatność CVE-2023-6779


Publikacja: 2024-01-31

Opis:
An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an incorrect calculation of the buffer size to store the message, resulting in an application crash. This issue affects glibc 2.37 and newer.

W naszej bazie, znaleźliśmy następujące noty dla tego CVE:
Tytuł
Autor
Data
High
glibc syslog() Heap-Based Buffer Overflow
Qualys Security ...
01.02.2024

Typ:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

 Referencje:
https://access.redhat.com/security/cve/CVE-2023-6779
https://bugzilla.redhat.com/show_bug.cgi?id=2254395
https://www.openwall.com/lists/oss-security/2024/01/30/6

Copyright 2024, cxsecurity.com

 

Back to Top