CVE-2023-2603: Integer Overflow
A vulnerability was found in libcap. This issue occurs in the libcapstrdup() function and can lead to an integer overflow if the input string is close to 4GiB.
Other sources
Original Report:
Source: libcap2 Version: 1:2.66-3 Severity: important Tags: security upstream X-Debbugs-Cc: carnil, Debian Security Team <team.org>
The following vulnerabilities were published for libcap2.
CVE-2023-2603[1]: | LCAP-CR-23-02 (Large strings can confuse libcap's internal strdup code)
[1] https://security-tracker.debian.org/tracker/CVE-2023-2603 https://www.cve.org/CVERecord?id=CVE-2023-2603
fixed in 1:2.66-4
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libcapto a version that resolves this vulnerability.Fixed in 0:2.48-5.el8_8 - Upgrade
Upgrade
redhat/libcapto a version that resolves this vulnerability.Fixed in 0:2.48-9.el9_2 - Upgrade
Upgrade
debian/libcap2to a version that resolves this vulnerability.Fixed in 1:2.66-4+deb12u3Fixed in 1:2.75-10+deb13u1Fixed in 1:2.78-1 - Upgrade
Upgrade
libcap2to a version that resolves this vulnerability.Fixed in 1:2.66-4Patch LCAP-CR-23-02
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-2603.
What is the severity of CVE-2023-2603?
The severity of CVE-2023-2603 is high.
What is the affected software for CVE-2023-2603?
The affected software for CVE-2023-2603 is libcap2, libcap, Redhat Enterprise Linux, Fedora, and Debian Debian Linux.
How does CVE-2023-2603 occur?
CVE-2023-2603 occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
Are there any fixes available for CVE-2023-2603?
Yes, there are fixes available for CVE-2023-2603. Please refer to the provided references for more information.