David Gstir discovered that libcap2 incorrectly handled certain return codes. An attacker could possibly use this issue to cause libcap2 to consume memory, leading to a denial of service. (CVE-2023-2602)
Richard Weinberger discovered that libcap2 incorrectly handled certain long input strings. An attacker could use this issue to cause libcap2 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-2603)
{ "binaries": [ { "binary_name": "libcap-dev", "binary_version": "1:2.32-1ubuntu0.1" }, { "binary_name": "libcap2", "binary_version": "1:2.32-1ubuntu0.1" }, { "binary_name": "libcap2-bin", "binary_version": "1:2.32-1ubuntu0.1" }, { "binary_name": "libpam-cap", "binary_version": "1:2.32-1ubuntu0.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "libcap-dev", "binary_version": "1:2.44-1ubuntu0.22.04.1" }, { "binary_name": "libcap2", "binary_version": "1:2.44-1ubuntu0.22.04.1" }, { "binary_name": "libcap2-bin", "binary_version": "1:2.44-1ubuntu0.22.04.1" }, { "binary_name": "libpam-cap", "binary_version": "1:2.44-1ubuntu0.22.04.1" } ], "availability": "No subscription required" }