First published: Wed May 10 2023(Updated: )
Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Oneapi Hpc Toolkit | <2023.0.0 | |
Intel Trace Analyzer and Collector | <2021.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23909 is a vulnerability in some Intel(R) Trace Analyzer and Collector software that allows an authenticated user to potentially enable information disclosure via local access.
CVE-2023-23909 has a severity rating of medium (5.5).
CVE-2023-23909 affects Intel(R) Trace Analyzer and Collector software versions before 2021.8.0 published in Dec 2022.
An authenticated user can potentially enable information disclosure via local access in Intel(R) Trace Analyzer and Collector software before version 2021.8.0.
Yes, the fix for CVE-2023-23909 is to upgrade to version 2021.8.0 or later of Intel(R) Trace Analyzer and Collector software.