CVE-2023-6779 is an off-by-one heap-based buffer overflow in the glibc library's __vsyslog_internal function, affecting glibc versions 2.37 and newer, including Fedora distributions. This vulnerability, triggered by syslog or vsyslog calls with messages exceeding INT_MAX bytes, leads to an application crash due to incorrect buffer size calculation. Rated 7.5 HIGH, it presents a network-based, low-complexity attack vector with high availability impact. While no public exploit code or active exploitation is reported, it has garnered community attention and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE match | cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:* | ||
>= 2.37, < 2.39CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.