NULL pointer dereference in iniparser - CVE-2023-33461
Published: June 28, 2023
Vulnerability identifier: #VU77773
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-33461
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the iniparser_getlongint() function. A remote attacker can pass specially crafted file to the application and perform a denial of service (DoS) attack.
Affected software
iniparser
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
Fedora
Server Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
libiniparser-devel
libiniparser0
libiniparser0-debuginfo
libiniparser0-32bit
libiniparser0-debuginfo-32bit
iniparser-debugsource
iniparser-doc
iniparser-devel
iniparser
libiniparser1 (Ubuntu package)
libiniparser1-32bit-debuginfo
libiniparser1-32bit
libiniparser1-64bit
libiniparser1-64bit-debuginfo
libiniparser1
libiniparser1-debuginfo
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
Fedora
Server Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
libiniparser-devel
libiniparser0
libiniparser0-debuginfo
libiniparser0-32bit
libiniparser0-debuginfo-32bit
iniparser-debugsource
iniparser-doc
iniparser-devel
iniparser
libiniparser1 (Ubuntu package)
libiniparser1-32bit-debuginfo
libiniparser1-32bit
libiniparser1-64bit
libiniparser1-64bit-debuginfo
libiniparser1
libiniparser1-debuginfo
How to mitigate CVE-2023-33461
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
libiniparser-devel - addressed in versions 3.1.0.git20140619_c5beb80a-3.3.1, 4.1-150500.4.3.1
libiniparser0 - update to 3.1.0.git20140619_c5beb80a-3.3.1
libiniparser0-debuginfo - update to 3.1.0.git20140619_c5beb80a-3.3.1
libiniparser0-32bit - update to 3.1.0.git20140619_c5beb80a-3.3.1
libiniparser0-debuginfo-32bit - update to 3.1.0.git20140619_c5beb80a-3.3.1
iniparser-debugsource - addressed in versions 3.1.0.git20140619_c5beb80a-3.3.1, 4.1-150500.4.3.1
iniparser-doc - update to 4.1-4
iniparser-devel - update to 4.1-4
iniparser - update to 4.1-4
iniparser - update to 4.1-4
libiniparser1 (Ubuntu package) - addressed in versions 4.1-4ubuntu4.1, 4.1-6ubuntu0.23.04.1, 4.1-6ubuntu0.23.10.1
iniparser - addressed in versions 4.1-6.el8, 4.1-11.fc37, 4.1-12.fc38
libiniparser1-32bit-debuginfo - update to 4.1-150500.4.3.1
libiniparser1-32bit - update to 4.1-150500.4.3.1
libiniparser1-64bit - update to 4.1-150500.4.3.1
libiniparser1-64bit-debuginfo - update to 4.1-150500.4.3.1
libiniparser1 - update to 4.1-150500.4.3.1
libiniparser1-debuginfo - update to 4.1-150500.4.3.1
libiniparser0 - update to 3.1.0.git20140619_c5beb80a-3.3.1
libiniparser0-debuginfo - update to 3.1.0.git20140619_c5beb80a-3.3.1
libiniparser0-32bit - update to 3.1.0.git20140619_c5beb80a-3.3.1
libiniparser0-debuginfo-32bit - update to 3.1.0.git20140619_c5beb80a-3.3.1
iniparser-debugsource - addressed in versions 3.1.0.git20140619_c5beb80a-3.3.1, 4.1-150500.4.3.1
iniparser-doc - update to 4.1-4
iniparser-devel - update to 4.1-4
iniparser - update to 4.1-4
iniparser - update to 4.1-4
libiniparser1 (Ubuntu package) - addressed in versions 4.1-4ubuntu4.1, 4.1-6ubuntu0.23.04.1, 4.1-6ubuntu0.23.10.1
iniparser - addressed in versions 4.1-6.el8, 4.1-11.fc37, 4.1-12.fc38
libiniparser1-32bit-debuginfo - update to 4.1-150500.4.3.1
libiniparser1-32bit - update to 4.1-150500.4.3.1
libiniparser1-64bit - update to 4.1-150500.4.3.1
libiniparser1-64bit-debuginfo - update to 4.1-150500.4.3.1
libiniparser1 - update to 4.1-150500.4.3.1
libiniparser1-debuginfo - update to 4.1-150500.4.3.1
External References
- https://github.com/ndevilla/iniparser/issues/144
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BQAIP5AURSTWIQOOP7G4CXYJ5IIGPY3Q/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ASV7SEDHGCP63GYAFEW3CTTVQDZM5RIK/