CVE-2023-2789

Name
CVE-2023-2789
Description
A vulnerability was found in GNU cflow 1.7. It has been rated as problematic. This issue affects the function func_body/parse_variable_declaration of the file parser.c. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. The identifier VDB-229373 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://vuldb.com/?id.229373
MISC https://vuldb.com/?ctiid.229373
MISC https://github.com/DaisyPo/fuzzing-vulncollect/files/11343936/poc-file.zip
MISC https://github.com/DaisyPo/fuzzing-vulncollect/blob/main/cflow/stack-overflow/parser.c/README.md

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:cflow:1.7:*:*:*:*:*:*:* cflow == None == 1.7

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
cflow edge-community 1.7-r0 qaqland <qaq@qaq.land> possibly vulnerable