CVE-2023-30362

NameCVE-2023-30362
DescriptionBuffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 allows attackers to obtain sensitive information via malformed pdu.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1040594

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libcoap3 (PTS)bookworm4.3.1-1vulnerable
sid, trixie4.3.4-1.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libcoap3source(unstable)4.3.1-21040594

Notes

[bookworm] - libcoap3 <ignored> (Minor issue, no reverse deps in Bookworm)
https://github.com/obgm/libcoap/issues/1063
https://github.com/obgm/libcoap/commit/e242200f0af2a418dc9f69eee543feacc13cd851

Search for package or bug name: Reporting problems