CVE-2023-22652: Stack buffer overflow in "read_file" function
Published Jun 1, 2023
·Updated
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via malformed config files. This issue affects libeconf: before 0.5.2.
Affected Software
2 affected componentsFixes available
openSUSE libeconf<0.5.2
debian/libeconf<=0.3.8-1
0.3.8-1+deb11u10.5.1+dfsg1-1+deb12u10.7.7+dfsg1-10.8.3+dfsg1-1
Event History
Jun 1, 2023
CVE Published
via MITRE·11:51 AM
Data Sourced
via MITRE·11:51 AM
DescriptionSeverityWeakness
Data Sourced
12:15 PM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 2, 2026
Data Sourced
via Ubuntu·04:38 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:39 PM
DescriptionAffected Software
Data Sourced
via Launchpad·04:39 PM
Description
Frequently Asked Questions
1
What is CVE-2023-22652?
CVE-2023-22652 is a Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability in openSUSE libeconf that leads to a DoS via malformed config files.
2
How does CVE-2023-22652 affect openSUSE libeconf?
CVE-2023-22652 affects openSUSE libeconf versions before 0.5.2.
3
What is the severity of CVE-2023-22652?
The severity of CVE-2023-22652 is medium, with a severity value of 6.5.
4
How can CVE-2023-22652 be exploited?
CVE-2023-22652 can be exploited by using malformed config files to trigger a buffer overflow.
5
Is there a fix available for CVE-2023-22652?
Yes, a fix is available for CVE-2023-22652 by updating to openSUSE libeconf version 0.5.2 or later.