Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-45284
HistoryNov 09, 2023 - 12:00 a.m.

CVE-2023-45284

2023-11-0900:00:00
ubuntu.com
ubuntu.com
22
windows
islocal function
reserved device names
vulnerability
fix
golang
rebuilding
impact
paths

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.3%

On Windows, The IsLocal function does not correctly detect reserved device
names in some cases. Reserved names followed by spaces, such as "COM1 ",
and reserved names โ€œCOMโ€ and โ€œLPTโ€ followed by superscript 1, 2, or 3, are
incorrectly reported as local. With fix, IsLocal now correctly reports
these names as non-local.

Notes

Author Note
mdeslaur Packages built using golang need to be rebuilt once the vulnerability has been fixed. This CVE entry does not list packages that need rebuilding outside of the main repository or the Ubuntu variants with PPA overlays.
rodrigo-zaiden may impact only Windows paths, a better triage of real impact, if any, is appreciated. closed related to CVE-2023-45283

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.3%