Lucene search

K
rosalinuxROSA LABROSA-SA-2023-2309
HistoryDec 19, 2023 - 8:40 a.m.

Advisory ROSA-SA-2023-2309

2023-12-1908:40:45
ROSA LAB
abf.rosalinux.ru
13
libcap
rosa virtualization 2.1
integer overflow

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Software: libcap 2.26
OS: ROSA Virtualization 2.1

package_evr_string: libcap-2.26-5.0.1.rv3.src.rpm

CVE-ID: CVE-2023-2603
BDU-ID: None
CVE-Crit: HIGH
CVE-DESC.: This issue occurs in _libcap_strdup() and can cause an integer overflow if the input string is close to 4 GB.
CVE-STATUS: Fixed
CVE-REV: To close, run the yum update libcap command

OSVersionArchitecturePackageVersionFilename
ROSAanynoarchlibcap< 2.26UNKNOWN

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%