Bugzilla – Bug 1214597
VUL-0: CVE-2023-30078: libeconf: Stack overflow in function econf_writeFile at atlibeconf/lib/libeconf.c
Last modified: 2023-09-06 15:16:17 UTC
CVE-2023-30078 A stack overflow vulnerability exists in function econf_writeFile in file atlibeconf/lib/libeconf.c in libeconf 0.5.1 allows attackers to cause a Denial of service or execute arbitrary code. References: https://raw.githubusercontent.com/yangjiageng/PoC/master/libeconf-PoC/tst-write-string-data.c https://github.com/openSUSE/libeconf/issues/178 https://github.com/yangjiageng/PoC/blob/master/libeconf-PoC/econf_writeFile_546 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-30078 https://bugzilla.redhat.com/show_bug.cgi?id=2234472 https://www.cve.org/CVERecord?id=CVE-2023-30078 https://github.com/openSUSE/libeconf/issues/178 https://github.com/yangjiageng/PoC/blob/master/libeconf-PoC/econf_writeFile_546 https://raw.githubusercontent.com/yangjiageng/PoC/master/libeconf-PoC/tst-write-string-data.c
ok, reopen
(In reply to Stoyan Manolov from comment #0) > CVE-2023-30078 > > A stack overflow vulnerability exists in function econf_writeFile in file > atlibeconf/lib/libeconf.c in libeconf 0.5.1 allows attackers to cause a > Denial of service or execute arbitrary code. > > References: > > https://raw.githubusercontent.com/yangjiageng/PoC/master/libeconf-PoC/tst- > write-string-data.c > https://github.com/openSUSE/libeconf/issues/178 This issue has already the Nr. : CVE-2023-32181 So which one shall I use for it ?
Also see: https://bugzilla.suse.com/show_bug.cgi?id=1211078
I will combine the bugs.... *** This bug has been marked as a duplicate of bug 1211078 ***