Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2023-6246 Details

Description

A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program name (the basename of argv[0]) is bigger than 1024 bytes, resulting in an application crash or local privilege escalation. This issue affects glibc 2.36 and newer.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://cert-portal.siemens.com/productcert/html/ssa-082556.html siemens-SADP
http://packetstormsecurity.com/files/176931/glibc-qsort-Out-Of-Bounds-Read-Write.html CVEExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html CVEExploitThird Party AdvisoryVDB Entry
https://access.redhat.com/security/cve/CVE-2023-6246 CVEThird Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2249053 CVEIssue TrackingThird Party Advisory

see all 25 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-787Out-of-bounds Write[email protected]
CWE-122Heap-based Buffer Overflow[email protected]

Affected Products

ProductVersions
gnu glibc
>= 2.36, < 2.39

CPE

  • cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
fedoraproject fedora
38
39

CPE

  • cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

16 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2023-6246
NVD Published Date:
Jan 31, 2024
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2023-6246 Details - Not Deferred