CVE-2023-2603

Name
CVE-2023-2603
Description
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdf
MISC https://bugzilla.redhat.com/show_bug.cgi?id=2209113
secalert@redhat.com https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZ57ICDLMVYEREXQGZWL4GWI7FRJCRQT/
secalert@redhat.com https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPEGCFMCN5KGCFX5Y2VTKR732TTD4ADW/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libcap_project:libcap:*:*:*:*:*:*:*:* libcap >= None < 2.66-4
cpe:2.3:a:libcap_project:libcap:*:*:*:*:*:*:*:* libcap >= None < 2.69

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libcap 3.17-main 2.66-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
libcap 3.16-main 2.64-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
libcap 3.15-main 2.61-r1 Natanael Copa <ncopa@alpinelinux.org> fixed