First published: Tue Sep 12 2023(Updated: )
Libcap is a library for getting and setting POSIX.1e (formerly POSIX 6) draft 15 capabilities.<br>Security Fix(es):<br><li> libcap: Integer Overflow in _libcap_strdup() (CVE-2023-2603)</li> <li> libcap: Memory Leak on pthread_create() Error (CVE-2023-2602)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libcap | <2.48-9.el9_2 | 2.48-9.el9_2 |
redhat/libcap | <2.48-9.el9_2 | 2.48-9.el9_2 |
redhat/libcap-debuginfo | <2.48-9.el9_2 | 2.48-9.el9_2 |
redhat/libcap-debuginfo | <2.48-9.el9_2 | 2.48-9.el9_2 |
redhat/libcap-debugsource | <2.48-9.el9_2 | 2.48-9.el9_2 |
redhat/libcap-debugsource | <2.48-9.el9_2 | 2.48-9.el9_2 |
redhat/libcap-devel | <2.48-9.el9_2 | 2.48-9.el9_2 |
redhat/libcap-devel | <2.48-9.el9_2 | 2.48-9.el9_2 |
redhat/libcap | <2.48-9.el9_2 | 2.48-9.el9_2 |
redhat/libcap-debuginfo | <2.48-9.el9_2 | 2.48-9.el9_2 |
redhat/libcap-debugsource | <2.48-9.el9_2 | 2.48-9.el9_2 |
redhat/libcap-devel | <2.48-9.el9_2 | 2.48-9.el9_2 |
redhat/libcap | <2.48-9.el9_2.aa | 2.48-9.el9_2.aa |
redhat/libcap-debuginfo | <2.48-9.el9_2.aa | 2.48-9.el9_2.aa |
redhat/libcap-debugsource | <2.48-9.el9_2.aa | 2.48-9.el9_2.aa |
redhat/libcap-devel | <2.48-9.el9_2.aa | 2.48-9.el9_2.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2023:5071 has a moderate severity rating.
RHSA-2023:5071 addresses CVE-2023-2602 and CVE-2023-2603 related to libcap.
To fix RHSA-2023:5071, upgrade libcap to version 2.48-9.el9_2 or later.
CVE-2023-2603 in RHSA-2023:5071 causes an integer overflow in _libcap_strdup().
CVE-2023-2602 leads to a memory leak on pthread_create() errors.