David Gstir discovered that libcap2 incorrectly handled certain return codes. An attacker could possibly use this issue to cause libcap2 to consume memory, leading to a denial of service. (CVE-2023-2602)
Richard Weinberger discovered that libcap2 incorrectly handled certain long input strings. An attacker could use this issue to cause libcap2 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-2603)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1:2.32-1ubuntu0.1", "binary_name": "libcap-dev" }, { "binary_version": "1:2.32-1ubuntu0.1", "binary_name": "libcap2" }, { "binary_version": "1:2.32-1ubuntu0.1", "binary_name": "libcap2-bin" }, { "binary_version": "1:2.32-1ubuntu0.1", "binary_name": "libcap2-bin-dbgsym" }, { "binary_version": "1:2.32-1ubuntu0.1", "binary_name": "libcap2-dbgsym" }, { "binary_version": "1:2.32-1ubuntu0.1", "binary_name": "libcap2-udeb" }, { "binary_version": "1:2.32-1ubuntu0.1", "binary_name": "libpam-cap" }, { "binary_version": "1:2.32-1ubuntu0.1", "binary_name": "libpam-cap-dbgsym" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1:2.44-1ubuntu0.22.04.1", "binary_name": "libcap-dev" }, { "binary_version": "1:2.44-1ubuntu0.22.04.1", "binary_name": "libcap2" }, { "binary_version": "1:2.44-1ubuntu0.22.04.1", "binary_name": "libcap2-bin" }, { "binary_version": "1:2.44-1ubuntu0.22.04.1", "binary_name": "libcap2-bin-dbgsym" }, { "binary_version": "1:2.44-1ubuntu0.22.04.1", "binary_name": "libcap2-dbgsym" }, { "binary_version": "1:2.44-1ubuntu0.22.04.1", "binary_name": "libpam-cap" }, { "binary_version": "1:2.44-1ubuntu0.22.04.1", "binary_name": "libpam-cap-dbgsym" } ] }