CVE-2023-39976: Buffer Overflow
Published Aug 8, 2023
·Updated
logblackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.
Affected Software
5 affected componentsFixes available
ubuntu/libqb<2.0.4-1ubuntu0.2
2.0.4-1ubuntu0.2
ubuntu/libqb<2.0.6-2ubuntu0.1
2.0.6-2ubuntu0.1
debian/libqb<=2.0.3-1, <=2.0.6-2
1.0.5-12.0.8-1
redhat/libqb<2.0.8
2.0.8
ClusterLabs libqb<2.0.8
Remediation
Patch Available
Event History
Aug 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:24 AM
Description
Frequently Asked Questions
1
What is CVE-2023-39976?
CVE-2023-39976 is a vulnerability in libqb before 2.0.8 that allows a buffer overflow via long log messages.
2
What is the severity of CVE-2023-39976?
CVE-2023-39976 has a severity score of 9.8 (Critical).
3
How does CVE-2023-39976 affect Clusterlabs Libqb?
CVE-2023-39976 affects Clusterlabs Libqb versions up to and excluding 2.0.8.
4
How does CVE-2023-39976 affect Ubuntu libqb?
CVE-2023-39976 affects Ubuntu libqb versions 2.0.4-1ubuntu0.2 and 2.0.6-2ubuntu0.1.
5
How can I fix CVE-2023-39976?
To fix CVE-2023-39976, update libqb to version 2.0.8 or later.