Stack-based buffer overflow in editorconfig-core-c - CVE-2023-0341
Published: February 8, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the ec_glob() function. A remote unauthenticated attacker can trick the victim to edit a specially crafted file, trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Fedora
Ubuntu
openEuler
libeditorconfig0 (Ubuntu package)
editorconfig (Ubuntu package)
libeditorconfig-dev (Ubuntu package)
app-text/editorconfig-core-c
editorconfig
editorconfig-libs
editorconfig-devel
editorconfig-debugsource
editorconfig-debuginfo
How to mitigate CVE-2023-0341
libeditorconfig0 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.12.1-1.1+deb11u1build0.20.04.1, 0.12.5-2.1ubuntu0.1
editorconfig (Ubuntu package) - addressed in versions Ubuntu Pro, 0.12.1-1.1+deb11u1build0.20.04.1, 0.12.5-2.1ubuntu0.1
libeditorconfig-dev (Ubuntu package) - update to Ubuntu Pro
app-text/editorconfig-core-c - update to 0.12.6
editorconfig - addressed in versions 0.12.6-1.el8, 0.12.6-1.el9, 0.12.6-1.fc37
editorconfig-libs - update to 0.12.6-3
editorconfig-devel - update to 0.12.6-3
editorconfig-debugsource - update to 0.12.6-3
editorconfig-debuginfo - update to 0.12.6-3
editorconfig - update to 0.12.6-3
External References
Related Security Bulletins
- Stack-based buffer overflow in EditorConfig
- Ubuntu update for editorconfig-core
- Fedora 37 update for editorconfig
- Fedora EPEL 9 update for editorconfig
- Fedora EPEL 8 update for editorconfig
- Gentoo update for EditorConfig core C library
- Ubuntu update for editorconfig-core
- openEuler 24.03 LTS SP1 update for editorconfig
- openEuler 24.03 LTS update for editorconfig
- openEuler 24.03 LTS SP3 update for editorconfig