Описание
On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 bytes, utf_16le_to_utf_8_truncated() can write data beyond the end of the provided buffer.
A flaw was found in libpcap on Windows. When libpcap converts a Windows error message containing 4-byte UTF-8 characters, the utf_16le_to_utf_8_truncated() function can write data beyond its allocated buffer. This out-of-bounds write can lead to data corruption, impacting the integrity of the system. Exploitation requires high privileges and local access, with high attack complexity.
Отчет
This vulnerability is rated Low for Red Hat as the flaw in libpcap specifically affects Windows operating systems. Red Hat products, including Red Hat Enterprise Linux and OpenShift Container Platform, are not affected as the vulnerable code is not present in their respective libpcap packages.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libpcap | Not affected | ||
| Red Hat Enterprise Linux 6 | libpcap | Not affected | ||
| Red Hat Enterprise Linux 7 | libpcap | Not affected | ||
| Red Hat Enterprise Linux 8 | libpcap | Not affected | ||
| Red Hat Enterprise Linux 9 | libpcap | Not affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
1.9 Low
CVSS3
Связанные уязвимости
On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 bytes, utf_16le_to_utf_8_truncated() can write data beyond the end of the provided buffer.
On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 bytes, utf_16le_to_utf_8_truncated() can write data beyond the end of the provided buffer.
On Windows only, if libpcap needs to convert a Windows error message t ...
On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 bytes, utf_16le_to_utf_8_truncated() can write data beyond the end of the provided buffer.
EPSS
1.9 Low
CVSS3