Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2023-22652
HistoryJun 01, 2023 - 12:15 p.m.

CVE-2023-22652

2023-06-0112:15:09
Alpine Linux Development Team
security.alpinelinux.org
8
buffer overflow
opensuse
libeconf
dos
config files.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

41.0%

A Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability in openSUSE libeconf leads to DoS via malformed config files.
This issue affects libeconf: before 0.5.2.

OSVersionArchitecturePackageVersionFilename
Alpine3.17-mainnoarchlibeconf= 0.4.7-r0UNKNOWN
Alpine3.16-mainnoarchlibeconf= 0.4.4-r0UNKNOWN
Alpine3.15-mainnoarchlibeconf= 0.4.2-r0UNKNOWN

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

41.0%