Bugzilla – Bug 1211078
VUL-0: CVE-2023-22652, CVE-2023-32181: libeconf: Two stack-buffer-overflow issues
Last modified: 2023-10-18 20:30:05 UTC
Can we assign CVEs to the following stack-buffer-overflow vulnerabilities: https://github.com/openSUSE/libeconf/issues/177 https://github.com/openSUSE/libeconf/issues/178
I've assigned two CVEs: - https://github.com/openSUSE/libeconf/issues/177: CVE-2023-22652 - https://github.com/openSUSE/libeconf/issues/178: CVE-2023-32181
SUSE:SLE-15-SP3:Update libeconf-0.4.4 SUSE:SLE-15-SP4:Update libeconf-0.4.6
I don't develop libeconf, schubi does.
So, from my side everything is done, but feel free to reopen it if still something is missed.
It has been rejected....
*** Bug 1214597 has been marked as a duplicate of this bug. ***
*** Bug 1214598 has been marked as a duplicate of this bug. ***
Next run. I have added the CVE numbers in the changes file: SUSE_SLE-15-SP3_Update (0) $ isc mr Using target project 'SUSE:Maintenance' 307077 SUSE_SLE-15-SP4_Update (0) $ isc mr Using target project 'SUSE:Maintenance' 307078
next run: SUSE_SLE-15-SP3_Update (0) $ isc mr Using target project 'SUSE:Maintenance' 307149 SUSE_SLE-15-SP4_Update (0) $ isc mr Using target project 'SUSE:Maintenance' 307150
SUSE-SU-2023:3639-1: An update that solves four vulnerabilities can now be installed. Category: security (moderate) Bug References: 1198165, 1211078 CVE References: CVE-2023-22652, CVE-2023-30078, CVE-2023-30079, CVE-2023-32181 Sources used: SUSE Manager Proxy 4.2 (src): libeconf-0.5.2-150300.3.11.1 SUSE Manager Retail Branch Server 4.2 (src): libeconf-0.5.2-150300.3.11.1 SUSE Manager Server 4.2 (src): libeconf-0.5.2-150300.3.11.1 SUSE Linux Enterprise Micro 5.1 (src): libeconf-0.5.2-150300.3.11.1 SUSE Linux Enterprise Micro 5.2 (src): libeconf-0.5.2-150300.3.11.1 SUSE Linux Enterprise Micro for Rancher 5.2 (src): libeconf-0.5.2-150300.3.11.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:3954-1: An update that solves four vulnerabilities can now be installed. Category: security (important) Bug References: 1211078 CVE References: CVE-2023-22652, CVE-2023-30078, CVE-2023-30079, CVE-2023-32181 Sources used: openSUSE Leap 15.4 (src): libeconf-0.5.2-150400.3.6.1 openSUSE Leap 15.5 (src): libeconf-0.5.2-150400.3.6.1 SUSE Linux Enterprise Micro for Rancher 5.3 (src): libeconf-0.5.2-150400.3.6.1 SUSE Linux Enterprise Micro 5.3 (src): libeconf-0.5.2-150400.3.6.1 SUSE Linux Enterprise Micro for Rancher 5.4 (src): libeconf-0.5.2-150400.3.6.1 SUSE Linux Enterprise Micro 5.4 (src): libeconf-0.5.2-150400.3.6.1 Basesystem Module 15-SP4 (src): libeconf-0.5.2-150400.3.6.1 Basesystem Module 15-SP5 (src): libeconf-0.5.2-150400.3.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:3954-2: An update that solves four vulnerabilities can now be installed. Category: security (important) Bug References: 1211078 CVE References: CVE-2023-22652, CVE-2023-30078, CVE-2023-30079, CVE-2023-32181 Sources used: SUSE Linux Enterprise Micro 5.5 (src): libeconf-0.5.2-150400.3.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.