MGASA-2023-0205

Source
https://advisories.mageia.org/MGASA-2023-0205.html
Import Source
https://advisories.mageia.org/MGASA-2023-0205.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2023-0205
Related
Published
2023-06-28T05:21:41Z
Modified
2023-06-28T04:05:48Z
Summary
Updated libcap packages fix security vulnerability
Details

A vulnerability was found in the pthreadcreate() function in libcap. This issue may allow a malicious actor to use cause _realpthreadcreate() to return an error, which can exhaust the process memory. (CVE-2023-2602)

A vulnerability was found in libcap. This issue occurs in the libcapstrdup() function and can lead to an integer overflow if the input string is close to 4GiB. (CVE-2023-2603)

References
Credits

Affected packages

Mageia:8 / libcap

Package

Name
libcap
Purl
pkg:rpm/mageia/libcap?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.46-1.1.mga8

Ecosystem specific

{
    "section": "core"
}