CVE-2023-2603
published 2023-06-06CVE-2023-2603: A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.57%
43.6th percentile
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libcap2 | < libcap2 1:2.66-4 (bookworm) | libcap2 1:2.66-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libcap_project | libcap | < 2.69 | 2.69 |
| libcap_project | libcap | — | — |
| msrc | cbl2_libcap_2.60-2_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_libcap_2.26-3_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libcap2 vulnerability
osv·2023-06-19·CVSS 7.8
CVE-2023-2603 [HIGH] libcap2 vulnerability
libcap2 vulnerability
USN-6166-1 fixed a vulnerability in libcap2. This update provides
the corresponding update for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM
and Ubuntu 18.04 ESM.
Original advisory details:
Richard Weinberger discovered that libcap2 incorrectly handled certain long
input strings. An attacker could use this issue to cause libcap2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-2603)
OSV
libcap2 vulnerabilities
osv·2023-06-14·CVSS 3.3
CVE-2023-2602 [LOW] libcap2 vulnerabilities
libcap2 vulnerabilities
David Gstir discovered that libcap2 incorrectly handled certain return
codes. An attacker could possibly use this issue to cause libcap2 to
consume memory, leading to a denial of service. (CVE-2023-2602)
Richard Weinberger discovered that libcap2 incorrectly handled certain long
input strings. An attacker could use this issue to cause libcap2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-2603)
OSV
CVE-2023-2603: A vulnerability was found in libcap
osv·2023-06-06·CVSS 7.8
CVE-2023-2603 [HIGH] CVE-2023-2603: A vulnerability was found in libcap
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
GHSA
GHSA-wp54-pwvg-rqq5: A vulnerability was found in libcap
ghsa_unreviewed·2023-06-06
CVE-2023-2603 [HIGH] CWE-190 GHSA-wp54-pwvg-rqq5: A vulnerability was found in libcap
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
Oracle
Oracle Oracle Communications Risk Matrix: Oracle Linux (libcap) — CVE-2023-2603
vendor_oracle·2023-10-15·CVSS 7.8
CVE-2023-2603 [HIGH] Oracle Oracle Communications Risk Matrix: Oracle Linux (libcap) — CVE-2023-2603
Oracle Oracle Communications Risk Matrix: Oracle Linux (libcap) vulnerability
CVE: CVE-2023-2603
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2023 (OCT 2023)
Ubuntu
libcap2 vulnerability
vendor_ubuntu·2023-06-19·CVSS 7.8
CVE-2023-2603 [HIGH] libcap2 vulnerability
Title: libcap2 vulnerability
Summary: libcap could be made to crash or possibly execute arbitrary code
if it received a specially crafted input.
USN-6166-1 fixed a vulnerability in libcap2. This update provides
the corresponding update for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM
and Ubuntu 18.04 ESM.
Original advisory details:
Richard Weinberger discovered that libcap2 incorrectly handled certain long
input strings. An attacker could use this issue to cause libcap2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-2603)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libcap2 vulnerabilities
vendor_ubuntu·2023-06-14·CVSS 3.3
CVE-2023-2602 [LOW] libcap2 vulnerabilities
Title: libcap2 vulnerabilities
Summary: Several security issues were fixed in libcap2.
David Gstir discovered that libcap2 incorrectly handled certain return
codes. An attacker could possibly use this issue to cause libcap2 to
consume memory, leading to a denial of service. (CVE-2023-2602)
Richard Weinberger discovered that libcap2 incorrectly handled certain long
input strings. An attacker could use this issue to cause libcap2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-2603)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
vendor_msrc·2023-06-13·CVSS 7.8
CVE-2023-2603 [HIGH] CWE-190 A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Red Hat
libcap: Integer Overflow in _libcap_strdup()
vendor_redhat·2023-05-16·CVSS 7.8
CVE-2023-2603 [HIGH] CWE-190 libcap: Integer Overflow in _libcap_strdup()
libcap: Integer Overflow in _libcap_strdup()
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
Statement: This vulnerability is rated by the security researchers who discovered it (linked in external references, see section 4.1.2) as a Moderate impact.
Package: compat-libcap1 (Red Hat Enterprise Linux 6) - Out of support scope
Package: libcap (Red Hat Enterprise Linux 6) - Out of support scope
Package: compat-libcap1 (Red Hat Enterprise Linux 7) - Out of support scope
Package: libcap (Red Hat Enterprise Linux 7) -
Debian
CVE-2023-2603: libcap2 - A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() f...
vendor_debian·2023·CVSS 7.8
CVE-2023-2603 [HIGH] CVE-2023-2603: libcap2 - A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() f...
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
Scope: local
bookworm: resolved (fixed in 1:2.66-4)
bullseye: resolved (fixed in 1:2.44-1+deb11u1)
forky: resolved (fixed in 1:2.66-4)
sid: resolved (fixed in 1:2.66-4)
trixie: resolved (fixed in 1:2.66-4)
No detection rules found.
No public exploits indexed.
Trailofbits
Celebrating our 2023 open-source contributions
blogs_trailofbits·2024-01-24
Celebrating our 2023 open-source contributions
At Trail of Bits, we pride ourselves on making our best tools open source, such as Slither, PolyTracker, and RPC Investigator. But while this post is about open source, it’s not about our tools…
In 2023, our employees submitted over 450 pull requests (PRs) that were merged into non-Trail of Bits repositories. This demonstrates our commitment to securing the software ecosystem as a whole and to improving software quality for everyone. A representative list of contributions appears at the end of this post, but here are some highlights:
- Sigstore-conformance, a vital component of our Sigstore initiative in open-source engineering, functions as an integration test suite for diverse Sigstore client implementations. Ensuring conformity to the Sigstore client testing suite, it rigorously evalu
Trailofbits
Celebrating our 2023 open-source contributions
blogs_trailofbits·2024-01-24
Celebrating our 2023 open-source contributions
At Trail of Bits, we pride ourselves on making our best tools open source, such as Slither , PolyTracker , and RPC Investigator . But while this post is about open source, it’s not about our tools…
In 2023, our employees submitted over 450 pull requests (PRs) that were merged into non-Trail of Bits repositories. This demonstrates our commitment to securing the software ecosystem as a whole and to improving software quality for everyone. A representative list of contributions appears at the end of this post, but here are some highlights:
Sigstore-conformance , a vital component of our Sigstore initiative in open-source engineering, functions as an integration test suite for diverse Sigstore client implementations. Ensuring conformity to the Sigstore client testing suite, it rigorously eva
https://bugzilla.redhat.com/show_bug.cgi?id=2209113https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZ57ICDLMVYEREXQGZWL4GWI7FRJCRQT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPEGCFMCN5KGCFX5Y2VTKR732TTD4ADW/https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdfhttps://bugzilla.redhat.com/show_bug.cgi?id=2209113https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZ57ICDLMVYEREXQGZWL4GWI7FRJCRQT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPEGCFMCN5KGCFX5Y2VTKR732TTD4ADW/https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdf
2023-06-06
Published