A stack overflow vulnerability exists in function read_file in atlibeconf/lib/getfilecontents.c in libeconf 0.5.1 allows attackers to cause a Denial of service or execute arbitrary code. References: https://raw.githubusercontent.com/yangjiageng/PoC/master/libeconf-PoC/tst-logindefs1.c https://github.com/openSUSE/libeconf/issues/177 https://github.com/yangjiageng/PoC/blob/master/libeconf-PoC/read_file_503
Created libeconf tracking bugs for this issue: Affects: fedora-all [bug 2235236]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2023:5458 https://access.redhat.com/errata/RHSA-2023:5458