An update for libcap is now available for openEuler-22.03-LTS
Security Advisory
openeuler-security@openeuler.org
openEuler security committee
openEuler-SA-2023-1345
Final
1.0
1.0
2023-06-10
Initial
2023-06-10
2023-06-10
openEuler SA Tool V1.0
2023-06-10
libcap security update
An update for libcap is now available for openEuler-22.03-LTS.
This is a library for getting and setting POSIX.1e (formerly POSIX 6) draft 15 capabilities.
Security Fix(es):
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.(CVE-2023-2602)
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.(CVE-2023-2603)
An update for libcap is now available for openEuler-22.03-LTS.
openEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
Medium
libcap
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1345
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2023-2602
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2023-2603
https://nvd.nist.gov/vuln/detail/CVE-2023-2602
https://nvd.nist.gov/vuln/detail/CVE-2023-2603
openEuler-22.03-LTS
libcap-devel-2.61-5.oe2203.aarch64.rpm
libcap-debuginfo-2.61-5.oe2203.aarch64.rpm
libcap-debugsource-2.61-5.oe2203.aarch64.rpm
libcap-2.61-5.oe2203.aarch64.rpm
libcap-help-2.61-5.oe2203.noarch.rpm
libcap-2.61-5.oe2203.src.rpm
libcap-debuginfo-2.61-5.oe2203.x86_64.rpm
libcap-debugsource-2.61-5.oe2203.x86_64.rpm
libcap-2.61-5.oe2203.x86_64.rpm
libcap-devel-2.61-5.oe2203.x86_64.rpm
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
2023-06-10
CVE-2023-2602
openEuler-22.03-LTS
Low
3.3
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
libcap security update
2023-06-10
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1345
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
2023-06-10
CVE-2023-2603
openEuler-22.03-LTS
Medium
4.4
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
libcap security update
2023-06-10
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1345