CVE-2023-5978: Incorrect libcap_net limitation list manipulation
In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the capnet libcasper(3) service incorrectly validates that updated constraints are strictly subsets of the active constraints. When only a list of resolvable domain names was specified without setting any other limitations, an application could submit a new list of domains including include entries not previously listed. This could permit the application to resolve domain names that were previously restricted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5978?
The severity of CVE-2023-5978 is high.
How does CVE-2023-5978 affect FreeBSD?
CVE-2023-5978 affects versions of FreeBSD 13-RELEASE before 13-RELEASE-p5.
What is the impact of CVE-2023-5978?
The impact of CVE-2023-5978 is that under certain circumstances, the cap_net libcasper(3) service incorrectly validates updated constraints.
How can CVE-2023-5978 be fixed?
To fix CVE-2023-5978, update to FreeBSD version 13-RELEASE-p5 or later.
Where can I find more information about CVE-2023-5978?
More information about CVE-2023-5978 can be found at https://security.freebsd.org/advisories/FreeBSD-SA-23:16.cap_net.asc.