CVE-2023-5978

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 8, 2023
Updated: Dec 14, 2023
CWE ID 269

Summary

CVE-2023-5978 is a vulnerability affecting FreeBSD 13-RELEASE versions before 13-RELEASE-p5. The issue lies in the libcasper(3) service's cap_net component, which mishandles constraint validation. When an application specifies a list of resolvable domain names without any other limitations, it can submit a new list that includes domains not previously allowed. This oversight could enable the application to resolve previously restricted domain names.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share