Severity
7.5HIGH
EPSS
0.7%
top 29.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31
Latest updateFeb 1

Description

An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an incorrect calculation of the buffer size to store the message, resulting in an application crash. This issue affects glibc 2.37 and newer.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:HExploitability: 3.9 | Impact: 4.2

Affected Packages2 packages

NVDgnu/glibc2.372.39
Debianglibc< 2.36-9+deb12u4+2

Also affects: Fedora 38, 39

🔴Vulnerability Details

3
GHSA
GHSA-p5vr-h433-qhqr: An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library2024-01-31
OSV
CVE-2023-6779: An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library2024-01-31
CVEList
Glibc: off-by-one heap-based buffer overflow in __vsyslog_internal()2024-01-31

📋Vendor Advisories

4
Ubuntu
GNU C Library vulnerabilities2024-02-01
Red Hat
glibc: off-by-one heap-based buffer overflow in __vsyslog_internal()2024-01-30
Microsoft
Glibc: off-by-one heap-based buffer overflow in __vsyslog_internal()2024-01-09
Debian
CVE-2023-6779: glibc - An off-by-one heap-based buffer overflow was found in the __vsyslog_internal fun...2023

🕵️Threat Intelligence

2
Qualys
Qualys TRU Discovers Important Vulnerabilities in GNU C Library’s syslog() | Qualys2024-01-30
Qualys
Qualys TRU Discovers Important Vulnerabilities in GNU C Library’s syslog()2024-01-30