Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-24056

Опубликовано: 21 янв. 2023
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.

A flaw was found in pkgconf, where a variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. This issue may lead to a buffer overflow, which can crash the software.

Отчет

pkgconf is a program which helps to configure compiler and linker flags for development libraries, & this security flaw can only crash while compiling/building a package in a development environment, hence that provides a very minimal Impact. Also Red Hat Enterprise Linux 8 and 9 provide the stack protector in gcc, FORTIFY_SOURCE in glibc to protect against heap based overflows.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8pkgconfFix deferred
Red Hat Enterprise Linux 9pkgconfFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2165034pkgconf: unbounded string expansion due to incorrect checks may result in buffer overflow

EPSS

Процентиль: 4%
0.00021
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.

CVSS3: 5.5
nvd
больше 2 лет назад

In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.

CVSS3: 5.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 5.5
debian
больше 2 лет назад

In pkgconf through 1.9.3, variable duplication can cause unbounded str ...

suse-cvrf
больше 2 лет назад

Security update for pkgconf

EPSS

Процентиль: 4%
0.00021
Низкий

5.5 Medium

CVSS3