Bugzilla – Bug 1214598
VUL-0: CVE-2023-30079: libeconf: Stack overflow in function read_file at atlibeconf/lib/getfilecontents.c
Last modified: 2023-09-06 15:17:07 UTC
CVE-2023-30079 A stack overflow vulnerability exists in function read_file in atlibeconf/lib/getfilecontents.c in libeconf 0.5.1 allows attackers to cause a Denial of service or execute arbitrary code. References: https://raw.githubusercontent.com/yangjiageng/PoC/master/libeconf-PoC/tst-logindefs1.c https://github.com/openSUSE/libeconf/issues/177 https://github.com/yangjiageng/PoC/blob/master/libeconf-PoC/read_file_503 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-30079 https://bugzilla.redhat.com/show_bug.cgi?id=2234595 https://www.cve.org/CVERecord?id=CVE-2023-30079 https://github.com/openSUSE/libeconf/issues/177 https://github.com/yangjiageng/PoC/blob/master/libeconf-PoC/read_file_503 https://raw.githubusercontent.com/yangjiageng/PoC/master/libeconf-PoC/tst-logindefs1.c
ok, reopen
(In reply to Stoyan Manolov from comment #0) > CVE-2023-30079 > > A stack overflow vulnerability exists in function read_file in > atlibeconf/lib/getfilecontents.c in libeconf 0.5.1 allows attackers to cause > a Denial of service or execute arbitrary code. > > References: > > https://raw.githubusercontent.com/yangjiageng/PoC/master/libeconf-PoC/tst- > logindefs1.c > https://github.com/openSUSE/libeconf/issues/177 The issue 177 has already the number CVE-2023-22652. So, which one shall I use ?
I will combine the bugs.... *** This bug has been marked as a duplicate of bug 1211078 ***