PT-2023-18604 · Opensuse+6 · Libeconf+6

Yangjiageng

·

Published

2023-06-01

·

Updated

2026-06-02

·

CVE-2023-22652

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libeconf versions prior to 0.5.2
Description A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to Denial of Service (DoS) via malformed config files.
Recommendations For versions prior to 0.5.2, update to version 0.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to malformed config files to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:4347
CVE-2023-22652
DLA-4164-1
OPENSUSE-SU-2023_3954-1
RHSA-2023:4347
RHSA-2023_4347
RLSA-2023:4347
SUSE-SU-2023:3639-1
SUSE-SU-2023:3954-1
SUSE-SU-2023:3954-2
SUSE-SU-2023_3954-1
SUSE-SU-2024:2426-1
USN-8368-1

Affected Products

Almalinux
Debian
Red Hat
Red Os
Rocky Linux
Suse
Libeconf