Lucene search

K
nvd[email protected]NVD:CVE-2023-5978
HistoryNov 08, 2023 - 9:15 a.m.

CVE-2023-5978

2023-11-0809:15:07
CWE-269
web.nvd.nist.gov
freebsd
security vulnerability
cap_net libcasper(3)

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.0005 Low

EPSS

Percentile

17.8%

In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updated constraints are strictly subsets of the active constraints. Β When only a listΒ of resolvable domain names was specified without setting any other limitations, an application could submit a new list of domains including include entries not previously listed. Β This could permit the application to resolve domain names that were previously restricted.

Affected configurations

NVD
Node
freebsdfreebsdRange13.0–13.2
OR
freebsdfreebsdMatch13.2-
OR
freebsdfreebsdMatch13.2p1
OR
freebsdfreebsdMatch13.2p2
OR
freebsdfreebsdMatch13.2p3
OR
freebsdfreebsdMatch13.2p4

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.0005 Low

EPSS

Percentile

17.8%