CVE-2023-36377

NameCVE-2023-36377
DescriptionBuffer Overflow vulnerability in mtrojnar osslsigncode v.2.3 and before allows a local attacker to execute arbitrary code via a crafted .exe, .sys, and .dll files.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1035875

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
osslsigncode (PTS)buster2.0-1vulnerable
bullseye2.1-1vulnerable
trixie, sid, bookworm2.5-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
osslsigncodesource(unstable)2.3.0-11035875

Notes

https://github.com/mtrojnar/osslsigncode/releases/tag/2.3

Search for package or bug name: Reporting problems