ID

VAR-202310-0065


CVE

CVE-2023-4911


TITLE

GNU Project  of  GNU C Library  Out-of-bounds write vulnerability in products from multiple vendors such as

Trust: 0.8

sources: JVNDB: JVNDB-2023-013913

DESCRIPTION

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges. GNU Project of GNU C Library Products from multiple vendors, such as the following, contain out-of-bounds write vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. ========================================================================== Ubuntu Security Notice USN-6409-1 October 03, 2023 glibc vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS Summary: Several security issues were fixed in GNU C Library. An attacker could possibly use this issue to perform a privilege escalation attack. (CVE-2023-4911) It was discovered that the GNU C Library incorrectly handled certain DNS responses when the system was configured in no-aaaa mode. A remote attacker could possibly use this issue to cause the GNU C Library to crash, resulting in a denial of service. This issue only affected Ubuntu 23.04. (CVE-2023-4527) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: libc6 2.37-0ubuntu2.1 Ubuntu 22.04 LTS: libc6 2.35-0ubuntu3.4 After a standard system update you need to reboot your computer to make all the necessary changes. Details can be found in the Qualys advisory at https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt For the oldstable distribution (bullseye), this problem has been fixed in version 2.31-13+deb11u7. For the stable distribution (bookworm), this problem has been fixed in version 2.36-9+deb12u3. This update includes fixes for CVE-2023-4527 and CVE-2023-4806 originally planned for the upcoming bookworm point release. We recommend that you upgrade your glibc packages. For the detailed security status of glibc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/glibc Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmUcTjRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0RwIg/9FzdAHadxCbk4N4Yg+aC3CmY68Z0Q2datcBWL5oLnplNNKcgsQqDDrbr4 WBphk1mQBusrOw5t5O2CAZitUk/mcQQ0bsV3YDPKTnKYswYkf6MXIfJ9Ck3uHJ0W yKVczC9g2ZLJ3uhpAIPiKro/XxKJRbek2WLJ+lgXnJz4akhwB1sd1nDEUOKz3gBH jvZj8UvjPHg1gwf1d5Xz4C3Kcd5aso8a/Tpr6iix7UJB8FZmfwlo+Oq4+/obPvJm n5Rj0x6R2GEH/edJylgzrVMOYc5bSZlTs0a4rm90oUHWYL9Y3bDIusJesSedy97H qra/DMFlQRs0JPejC+TUhLmJWvOum30WrPpdQtjSAcWuxKTse/felwyDwwQ3ogP5 tzUOeG/YmHj8kT0owAFUFiQumOifMTVNO2SYHCO3jXSLkMCOw1f9NCmcV3wU05Pe cmFJgiZpzYzg4oY+MOnJAHfryQL4RGhv+VyPk5nhMa9F8405xSvl7did0FPz7YLX aWLAm8xhO/+ZIDowfKGK54zaDt2DHqId7VGNgn196ES8abuY71Le9zj1SIkZIXdA KwEwgGTSxkfWs/ffuzrn7gvmDLvB1u1Gb27Cq3M/WoVlxqGzmufyZM8t9xJhomEY BUNpA4jr0ZKxw5t5oss8xh95OVRCCjK6HAeTbpMXWbeEVCQjV30=j3fR -----END PGP SIGNATURE----- . - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202310-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: glibc: Multiple vulnerabilities Date: October 04, 2023 Bugs: #867952, #914281, #915127 ID: 202310-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in glibc could result in Local Privilege Escalation. Background ========= glibc is a package that contains the GNU C library. Affected packages ================ Package Vulnerable Unaffected -------------- ------------ ------------ sys-libs/glibc < 2.37-r7 >= 2.37-r7 Description ========== Multiple vulnerabilities have been discovered in glibc. Please review the CVE identifiers referenced below for details. Impact ===== An attacker could elevate privileges from a local user to root. Workaround ========= There is no known workaround at this time. Resolution ========= All glibc users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=sys-libs/glibc-2.37-r7" References ========= [ 1 ] CVE-2022-39046 https://nvd.nist.gov/vuln/detail/CVE-2022-39046 [ 2 ] CVE-2023-4527 https://nvd.nist.gov/vuln/detail/CVE-2023-4527 [ 3 ] CVE-2023-4806 https://nvd.nist.gov/vuln/detail/CVE-2023-4806 [ 4 ] CVE-2023-4911 https://nvd.nist.gov/vuln/detail/CVE-2023-4911 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202310-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2023 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . The following advisory data is extracted from: https://access.redhat.com/security/data/csaf/v2/advisories/2024/rhsa-2024_0033.json Red Hat officially shut down their mailing list notifications October 10, 2023. Due to this, Packet Storm has recreated the below data as a reference point to raise awareness. It must be noted that due to an inability to easily track revision updates without crawling Red Hat's archive, these advisories are single notifications and we strongly suggest that you visit the Red Hat provided links to ensure you have the latest information available if the subject matter listed pertains to your environment. - Packet Storm Staff ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Virtualization Host 4.4.z SP 1 security update Advisory ID: RHSA-2024:0033-03 Product: Red Hat Virtualization Advisory URL: https://access.redhat.com/errata/RHSA-2024:0033 Issue date: 2024-01-03 Revision: 03 CVE Names: CVE-2023-4911 ==================================================================== Summary: An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description: The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks. Security Fix(es): For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution: https://access.redhat.com/articles/2974891 CVEs: CVE-2023-4911 References: https://access.redhat.com/security/updates/classification/#moderate https://bugzilla.redhat.com/show_bug.cgi?id=2238352

Trust: 1.98

sources: NVD: CVE-2023-4911 // JVNDB: JVNDB-2023-013913 // PACKETSTORM: 174908 // PACKETSTORM: 174906 // PACKETSTORM: 174914 // PACKETSTORM: 176372

AFFECTED PRODUCTS

vendor:siemensmodel:simatic s7-1500 cpu 1518-4 pn\/dp mfpscope:gteversion:3.1.5

Trust: 1.0

vendor:redhatmodel:codeready linux builder for arm64scope:eqversion:9.0_aarch64

Trust: 1.0

vendor:redhatmodel:codeready linux builder for power little endianscope:eqversion:9.0_ppc64le

Trust: 1.0

vendor:redhatmodel:codeready linux builder for arm64 eusscope:eqversion:8.6

Trust: 1.0

vendor:gnumodel:glibcscope:ltversion:2.39

Trust: 1.0

vendor:redhatmodel:enterprise linux for arm 64 eusscope:eqversion:9.4_aarch64

Trust: 1.0

vendor:redhatmodel:enterprise linux for power big endian eusscope:eqversion:8.6_ppc64le

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:39

Trust: 1.0

vendor:redhatmodel:enterprise linux server for power little endian update services for sap solutionsscope:eqversion:9.6_ppc64le

Trust: 1.0

vendor:redhatmodel:codeready linux builder for power little endian eusscope:eqversion:9.4_ppc64le

Trust: 1.0

vendor:redhatmodel:virtualizationscope:eqversion:4.0

Trust: 1.0

vendor:redhatmodel:codeready linux builder for power little endian eusscope:eqversion:9.2_ppc64le

Trust: 1.0

vendor:redhatmodel:codeready linux builder for power little endian eusscope:eqversion:8.6

Trust: 1.0

vendor:redhatmodel:codeready linux builder for ibm z systemsscope:eqversion:9.0_s390x

Trust: 1.0

vendor:redhatmodel:enterprise linux server tusscope:eqversion:8.6

Trust: 1.0

vendor:redhatmodel:enterprise linux eusscope:eqversion:8.6

Trust: 1.0

vendor:netappmodel:ontap select deploy administration utilityscope:eqversion: -

Trust: 1.0

vendor:netappmodel:h700sscope:eqversion: -

Trust: 1.0

vendor:redhatmodel:enterprise linux update services for sap solutionsscope:eqversion:9.2

Trust: 1.0

vendor:netappmodel:h500sscope:eqversion: -

Trust: 1.0

vendor:redhatmodel:enterprise linux eusscope:eqversion:9.4

Trust: 1.0

vendor:redhatmodel:codeready linux builder for ibm z systems eusscope:eqversion:9.4_s390x

Trust: 1.0

vendor:redhatmodel:enterprise linuxscope:eqversion:8.0

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:12.0

Trust: 1.0

vendor:redhatmodel:codeready linux builderscope:eqversion:9.0

Trust: 1.0

vendor:redhatmodel:codeready linux builder eusscope:eqversion:9.2

Trust: 1.0

vendor:redhatmodel:enterprise linuxscope:eqversion:9.0

Trust: 1.0

vendor:redhatmodel:enterprise linux for arm 64 eusscope:eqversion:8.6_aarch64

Trust: 1.0

vendor:redhatmodel:enterprise linux for power little endian eusscope:eqversion:9.6_ppc64le

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:11.0

Trust: 1.0

vendor:netappmodel:h410cscope:eqversion: -

Trust: 1.0

vendor:redhatmodel:enterprise linux server ausscope:eqversion:9.2

Trust: 1.0

vendor:netappmodel:bootstrap osscope:eqversion: -

Trust: 1.0

vendor:redhatmodel:enterprise linux eusscope:eqversion:9.6

Trust: 1.0

vendor:redhatmodel:enterprise linux for arm 64scope:eqversion:9.0_aarch64

Trust: 1.0

vendor:redhatmodel:virtualization hostscope:eqversion:4.0

Trust: 1.0

vendor:gnumodel:glibcscope:gteversion:2.34

Trust: 1.0

vendor:siemensmodel:simatic s7-1500 tm mfpscope:ltversion:1.1

Trust: 1.0

vendor:redhatmodel:codeready linux builder for power little endian eusscope:eqversion:9.6_ppc64le

Trust: 1.0

vendor:siemensmodel:simatic s7-1500 cpu 1518f-4 pn\/dp mfpscope:gteversion:3.1.5

Trust: 1.0

vendor:redhatmodel:codeready linux builder eusscope:eqversion:8.6

Trust: 1.0

vendor:redhatmodel:enterprise linux for ibm z systems eusscope:eqversion:9.4_s390x

Trust: 1.0

vendor:redhatmodel:enterprise linux server for power little endian update services for sap solutionsscope:eqversion:9.4_ppc64le

Trust: 1.0

vendor:redhatmodel:enterprise linux server for power little endian update services for sap solutionsscope:eqversion:9.2_ppc64le

Trust: 1.0

vendor:redhatmodel:codeready linux builder for ibm z systems eusscope:eqversion:9.2_s390x

Trust: 1.0

vendor:redhatmodel:enterprise linux for arm 64 eusscope:eqversion:9.2_aarch64

Trust: 1.0

vendor:redhatmodel:enterprise linux for ibm z systemsscope:eqversion:9.0_s390x

Trust: 1.0

vendor:redhatmodel:enterprise linux server ausscope:eqversion:8.6

Trust: 1.0

vendor:redhatmodel:enterprise linux update services for sap solutionsscope:eqversion:9.4

Trust: 1.0

vendor:netappmodel:h300sscope:eqversion: -

Trust: 1.0

vendor:redhatmodel:codeready linux builder eusscope:eqversion:9.4

Trust: 1.0

vendor:redhatmodel:enterprise linux update services for sap solutionsscope:eqversion:9.6

Trust: 1.0

vendor:redhatmodel:enterprise linux server ausscope:eqversion:9.4

Trust: 1.0

vendor:redhatmodel:codeready linux builder for ibm z systems eusscope:eqversion:9.6_s390x

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:22.04

Trust: 1.0

vendor:redhatmodel:enterprise linux for power little endianscope:eqversion:9.0_ppc64le

Trust: 1.0

vendor:redhatmodel:codeready linux builder eusscope:eqversion:9.6

Trust: 1.0

vendor:redhatmodel:enterprise linux for ibm z systems eusscope:eqversion:9.2_s390x

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:37

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:23.04

Trust: 1.0

vendor:redhatmodel:enterprise linux server ausscope:eqversion:9.6

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:38

Trust: 1.0

vendor:netappmodel:h410sscope:eqversion: -

Trust: 1.0

vendor:redhatmodel:codeready linux builder for arm64 eusscope:eqversion:9.6_aarch64

Trust: 1.0

vendor:redhatmodel:enterprise linux for ibm z systems eus s390xscope:eqversion:8.6

Trust: 1.0

vendor:redhatmodel:codeready linux builder for arm64 eusscope:eqversion:9.2_aarch64

Trust: 1.0

vendor:redhatmodel:codeready linux builder for arm64 eusscope:eqversion:9.4_aarch64

Trust: 1.0

vendor:redhatmodel:enterprise linux for ibm z systems eusscope:eqversion:9.6_s390x

Trust: 1.0

vendor:redhatmodel:enterprise linux for power little endian eusscope:eqversion:9.4_ppc64le

Trust: 1.0

vendor:siemensmodel:siplus s7-1500 cpu 1518-4 pn\/dp mfpscope:gteversion:3.1.5

Trust: 1.0

vendor:redhatmodel:enterprise linux eusscope:eqversion:9.2

Trust: 1.0

vendor:redhatmodel:enterprise linux for power little endian eusscope:eqversion:9.2_ppc64le

Trust: 1.0

vendor:redhatmodel:codeready linux builder for ibm z systems eusscope:eqversion:8.6

Trust: 1.0

vendor:redhatmodel:enterprise linux for arm 64 eusscope:eqversion:9.6_aarch64

Trust: 1.0

vendor:gnumodel:c libraryscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise linuxscope: - version: -

Trust: 0.8

vendor:fedoramodel:fedorascope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat virtualizationscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2023-013913 // NVD: CVE-2023-4911

CVSS

SEVERITY

CVSSV2

CVSSV3

secalert@redhat.com: CVE-2023-4911
value: HIGH

Trust: 1.0

nvd@nist.gov: CVE-2023-4911
value: HIGH

Trust: 1.0

NVD: CVE-2023-4911
value: HIGH

Trust: 0.8

secalert@redhat.com: CVE-2023-4911
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 2.0

NVD: CVE-2023-4911
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2023-013913 // NVD: CVE-2023-4911 // NVD: CVE-2023-4911

PROBLEMTYPE DATA

problemtype:CWE-122

Trust: 1.0

problemtype:CWE-787

Trust: 1.0

problemtype:Out-of-bounds writing (CWE-787) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2023-013913 // NVD: CVE-2023-4911

THREAT TYPE

remote

Trust: 0.1

sources: PACKETSTORM: 174908

TYPE

overflow

Trust: 0.5

sources: PACKETSTORM: 174906 // PACKETSTORM: 174976 // PACKETSTORM: 174968 // PACKETSTORM: 174966 // PACKETSTORM: 174963

EXTERNAL IDS

db:NVDid:CVE-2023-4911

Trust: 3.4

db:PACKETSTORMid:176288

Trust: 1.8

db:PACKETSTORMid:174986

Trust: 1.8

db:OPENWALLid:OSS-SECURITY/2023/10/14/6

Trust: 1.8

db:OPENWALLid:OSS-SECURITY/2023/10/13/11

Trust: 1.8

db:OPENWALLid:OSS-SECURITY/2023/10/14/5

Trust: 1.8

db:OPENWALLid:OSS-SECURITY/2023/10/05/1

Trust: 1.8

db:OPENWALLid:OSS-SECURITY/2023/10/14/3

Trust: 1.8

db:OPENWALLid:OSS-SECURITY/2023/10/03/2

Trust: 1.8

db:OPENWALLid:OSS-SECURITY/2023/10/03/3

Trust: 1.8

db:EXPLOIT-DBid:52479

Trust: 1.0

db:SIEMENSid:SSA-794697

Trust: 1.0

db:SIEMENSid:SSA-831302

Trust: 1.0

db:SIEMENSid:SSA-082556

Trust: 1.0

db:ICS CERTid:ICSA-25-162-05

Trust: 0.8

db:ICS CERTid:ICSA-23-348-10

Trust: 0.8

db:JVNid:JVNVU98271228

Trust: 0.8

db:JVNid:JVNVU96443907

Trust: 0.8

db:JVNDBid:JVNDB-2023-013913

Trust: 0.8

db:PACKETSTORMid:174908

Trust: 0.1

db:PACKETSTORMid:174906

Trust: 0.1

db:PACKETSTORMid:174914

Trust: 0.1

db:PACKETSTORMid:176372

Trust: 0.1

db:PACKETSTORMid:174976

Trust: 0.1

db:PACKETSTORMid:174968

Trust: 0.1

db:PACKETSTORMid:174966

Trust: 0.1

db:PACKETSTORMid:174963

Trust: 0.1

sources: PACKETSTORM: 174908 // PACKETSTORM: 174906 // PACKETSTORM: 174914 // PACKETSTORM: 176372 // PACKETSTORM: 174976 // PACKETSTORM: 174968 // PACKETSTORM: 174966 // PACKETSTORM: 174963 // JVNDB: JVNDB-2023-013913 // NVD: CVE-2023-4911

REFERENCES

url:https://access.redhat.com/security/cve/cve-2023-4911

Trust: 2.2

url:https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt

Trust: 1.9

url:https://security.gentoo.org/glsa/202310-03

Trust: 1.9

url:https://bugzilla.redhat.com/show_bug.cgi?id=2238352

Trust: 1.9

url:https://access.redhat.com/errata/rhsa-2023:5476

Trust: 1.9

url:https://access.redhat.com/errata/rhsa-2023:5455

Trust: 1.9

url:https://access.redhat.com/errata/rhsa-2023:5453

Trust: 1.9

url:https://access.redhat.com/errata/rhsa-2023:5454

Trust: 1.9

url:http://packetstormsecurity.com/files/174986/glibc-ld.so-local-privilege-escalation.html

Trust: 1.8

url:http://packetstormsecurity.com/files/176288/glibc-tunables-privilege-escalation.html

Trust: 1.8

url:http://seclists.org/fulldisclosure/2023/oct/11

Trust: 1.8

url:http://www.openwall.com/lists/oss-security/2023/10/03/2

Trust: 1.8

url:http://www.openwall.com/lists/oss-security/2023/10/03/3

Trust: 1.8

url:http://www.openwall.com/lists/oss-security/2023/10/05/1

Trust: 1.8

url:http://www.openwall.com/lists/oss-security/2023/10/13/11

Trust: 1.8

url:http://www.openwall.com/lists/oss-security/2023/10/14/3

Trust: 1.8

url:http://www.openwall.com/lists/oss-security/2023/10/14/5

Trust: 1.8

url:http://www.openwall.com/lists/oss-security/2023/10/14/6

Trust: 1.8

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4dbuqrrpb47tc3njouibvwugfhbjafdl/

Trust: 1.8

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/dfg4p76uhhzewq26fwbxg76n2qlkkpza/

Trust: 1.8

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ndaqwhtsvocoz5k6kpiwkrt3jx4rtzur/

Trust: 1.8

url:https://security.netapp.com/advisory/ntap-20231013-0006/

Trust: 1.8

url:https://www.debian.org/security/2023/dsa-5514

Trust: 1.8

url:https://www.qualys.com/cve-2023-4911/

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2023-4911

Trust: 1.6

url:https://access.redhat.com/errata/rhsa-2024:0033

Trust: 1.1

url:https://cert-portal.siemens.com/productcert/html/ssa-082556.html

Trust: 1.0

url:https://cert-portal.siemens.com/productcert/html/ssa-794697.html

Trust: 1.0

url:https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=cve-2023-4911

Trust: 1.0

url:https://cert-portal.siemens.com/productcert/html/ssa-831302.html

Trust: 1.0

url:https://www.exploit-db.com/exploits/52479

Trust: 1.0

url:https://jvn.jp/vu/jvnvu98271228/

Trust: 0.8

url:https://jvn.jp/vu/jvnvu96443907/

Trust: 0.8

url:https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-23-348-10

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2023-4527

Trust: 0.4

url:https://bugzilla.redhat.com/):

Trust: 0.4

url:https://access.redhat.com/security/team/key/

Trust: 0.4

url:https://access.redhat.com/security/team/contact/

Trust: 0.4

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.4

url:https://listman.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.4

url:https://access.redhat.com/articles/11258

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2023-4806

Trust: 0.3

url:https://access.redhat.com/security/cve/cve-2023-4813

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2023-4813

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2023-4806

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2023-4527

Trust: 0.2

url:https://launchpad.net/ubuntu/+source/glibc/2.35-0ubuntu3.4

Trust: 0.1

url:https://ubuntu.com/security/notices/usn-6409-1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/glibc/2.37-0ubuntu2.1

Trust: 0.1

url:https://security-tracker.debian.org/tracker/glibc

Trust: 0.1

url:https://www.debian.org/security/faq

Trust: 0.1

url:https://www.debian.org/security/

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:https://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-39046

Trust: 0.1

url:https://security.gentoo.org/

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#moderate

Trust: 0.1

url:https://access.redhat.com/articles/2974891

Trust: 0.1

url:https://access.redhat.com/security/data/csaf/v2/advisories/2024/rhsa-2024_0033.json

Trust: 0.1

sources: PACKETSTORM: 174908 // PACKETSTORM: 174906 // PACKETSTORM: 174914 // PACKETSTORM: 176372 // PACKETSTORM: 174976 // PACKETSTORM: 174968 // PACKETSTORM: 174966 // PACKETSTORM: 174963 // JVNDB: JVNDB-2023-013913 // NVD: CVE-2023-4911

CREDITS

Red Hat

Trust: 0.5

sources: PACKETSTORM: 176372 // PACKETSTORM: 174976 // PACKETSTORM: 174968 // PACKETSTORM: 174966 // PACKETSTORM: 174963

SOURCES

db:PACKETSTORMid:174908
db:PACKETSTORMid:174906
db:PACKETSTORMid:174914
db:PACKETSTORMid:176372
db:PACKETSTORMid:174976
db:PACKETSTORMid:174968
db:PACKETSTORMid:174966
db:PACKETSTORMid:174963
db:JVNDBid:JVNDB-2023-013913
db:NVDid:CVE-2023-4911

LAST UPDATE DATE

2026-06-18T19:45:37.682000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2023-013913date:2025-06-16T06:35:00
db:NVDid:CVE-2023-4911date:2026-05-12T16:24:45.860

SOURCES RELEASE DATE

db:PACKETSTORMid:174908date:2023-10-04T15:04:05
db:PACKETSTORMid:174906date:2023-10-04T15:03:24
db:PACKETSTORMid:174914date:2023-10-04T15:05:38
db:PACKETSTORMid:176372date:2024-01-04T13:18:04
db:PACKETSTORMid:174976date:2023-10-06T14:45:56
db:PACKETSTORMid:174968date:2023-10-06T14:44:25
db:PACKETSTORMid:174966date:2023-10-06T14:44:04
db:PACKETSTORMid:174963date:2023-10-06T14:43:34
db:JVNDBid:JVNDB-2023-013913date:2023-12-22T00:00:00
db:NVDid:CVE-2023-4911date:2023-10-03T18:15:10.463