CVE-2023-6780

Severity
5.3MEDIUM
EPSS
0.2%
top 55.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31
Latest updateFeb 1

Description

An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDgnu/glibc2.372.39
Debianglibc< 2.36-9+deb12u4+2

Also affects: Fedora 38, 39

🔴Vulnerability Details

3
CVEList
Glibc: integer overflow in __vsyslog_internal()2024-01-31
OSV
CVE-2023-6780: An integer overflow was found in the __vsyslog_internal function of the glibc library2024-01-31
GHSA
GHSA-jjr8-97p7-vmmg: An integer overflow was found in the __vsyslog_internal function of the glibc library2024-01-31

📋Vendor Advisories

4
Ubuntu
GNU C Library vulnerabilities2024-02-01
Red Hat
glibc: integer overflow in __vsyslog_internal()2024-01-30
Microsoft
Glibc: integer overflow in __vsyslog_internal()2024-01-09
Debian
CVE-2023-6780: glibc - An integer overflow was found in the __vsyslog_internal function of the glibc li...2023

🕵️Threat Intelligence

2
Qualys
Qualys TRU Discovers Important Vulnerabilities in GNU C Library’s syslog() | Qualys2024-01-30
Qualys
Qualys TRU Discovers Important Vulnerabilities in GNU C Library’s syslog()2024-01-30
CVE-2023-6780 (MEDIUM CVSS 5.3) | An integer overflow was found in th | cvebase.io