CVE-2023-28753: Integer Overflow
netconsd prior to v0.2 was vulnerable to an integer overflow in its parsepacket function. A malicious individual could leverage this overflow to create heap memory corruption with attacker controlled data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2023-28753.
What is the severity rating of CVE-2023-28753?
The severity rating of CVE-2023-28753 is critical (9.8).
Which software versions are affected by CVE-2023-28753?
The software version affected by CVE-2023-28753 is netconsd prior to v0.2, specifically version 0.1.
How can this vulnerability be exploited?
This vulnerability can be exploited by leveraging an integer overflow in the parse_packet function of netconsd to create heap memory corruption with attacker-controlled data.
Where can I find more information about CVE-2023-28753?
You can find more information about CVE-2023-28753 at the following references: [GitHub Commit](https://github.com/facebook/netconsd/commit/9fc54edf54f7caea1189c2b979337ed37af2c60e) and [Facebook Security Advisories](https://www.facebook.com/security/advisories/cve-2023-28753).