UBUNTU-CVE-2023-46046

Source
https://ubuntu.com/security/CVE-2023-46046
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46046.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2023-46046
Withdrawn
2025-06-23T15:56:55Z
Published
2024-03-27T05:15:00Z
Modified
2024-03-27T05:15:00Z
Summary
[none]
Details

** DISPUTED ** An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is disputed because there is no common libminizinc use case in which an unattended process is supposed to run forever to process a series of atttacker-controlled .mzn files.

References

Affected packages

Ubuntu:Pro:16.04:LTS / minizinc

Package

Name
minizinc
Purl
pkg:deb/ubuntu/minizinc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.8+dfsg1-1
2.0.10+dfsg1-1
2.0.11+dfsg1-1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46046.json"

Ubuntu:Pro:18.04:LTS / minizinc

Package

Name
minizinc
Purl
pkg:deb/ubuntu/minizinc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.14+dfsg1-1
2.1.5+dfsg1-1
2.1.7+dfsg1-1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46046.json"

Ubuntu:20.04:LTS / minizinc

Package

Name
minizinc
Purl
pkg:deb/ubuntu/minizinc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.1.7+dfsg1-1
2.4.2-1
2.4.2-1build1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46046.json"

Ubuntu:22.04:LTS / minizinc

Package

Name
minizinc
Purl
pkg:deb/ubuntu/minizinc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.5.3+dfsg1-1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46046.json"

Ubuntu:24.04:LTS / minizinc

Package

Name
minizinc
Purl
pkg:deb/ubuntu/minizinc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.4+dfsg1-1
2.8.2+dfsg1-1
2.8.2+dfsg1-1build1
2.8.2+dfsg1-1build2

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46046.json"