UBUNTU-CVE-2023-28488
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-28488
UBUNTU-CVE-2023-28488
Summary:
Details: client.c in gdhcp in ConnMan through 1.41 could be used by network-adjacent attackers (operating a crafted DHCP server) to cause a stack-based buffer overflow and denial of service, terminating the connman process.
References: https://ubuntu.com/security/CVE-2023-28488, https://github.com/moehw/poc_exploits/tree/master/CVE-2023-28488, https://git.kernel.org/pub/scm/network/connman/connman.git/commit/?id=99e2c16ea1cced34a5dc450d76287a1c3e762138, https://kernel.googlesource.com/pub/scm/network/connman/connman/+/99e2c16ea1cced34a5dc450d76287a1c3e762138, https://ubuntu.com/security/notices/USN-6236-1, https://www.cve.org/CVERecord?id=CVE-2023-28488
Affected packages
Package
Name: connman
Purl: pkg:deb/ubuntu/[email protected]+deb8u1ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
