Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Two separate issues where identified and have now been adressed in libmodbus. For one of the problems multiple CVE identifiers have been allocated to the same issue and all of them are mentioned below. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4084-1
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libmodbus ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10196-1 Rating: important References: #1195124 Cross-References: CVE-2022-0367 CVSS scores: CVE-2022-0367 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libmodbus fixes the following issues: - CVE-2022-0367: Fixed heap-based Buffer Overflow in modbus_reply (boo#1195124). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10196=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): libmodbus-devel-3.1.6-bp154.2.3.1 libmodbus5-3.1.6-bp154.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-0367.html https://bugzilla.suse.com/1195124 . Important security patch released for libmodbus concerning CVE-2022-0367. Address the buffer overflow vulnerability immediately!. openSUSE Update, libmodbus Patch, Security Advisory, Buffer Overflow Fix. . Severity: Important. LinuxSecurity.com Team
A heap-based buffer overflow flaw was found in libmodbus, a library for the Modbus protocol, which can be abused for a denial of service attack or memory corruption. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3098-1
libmodbus could be made to crash if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-5173-1 December 06, 2021 libmodbus vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: libmodbus could be made to crash if it received specially crafted input. Software Description: - libmodbus: Library to send/receive data according to the Modbus protocol Details: It was discovered that libmodbus incorrectly handled inputs. An attacker could possibly use this issue to cause a denial of service or other unspecified impact. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libmodbus5 3.0.6-2+deb9u1build0.18.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5173-1 CVE-2019-14462, CVE-2019-14463 Package Information: https://launchpad.net/ubuntu/+source/libmodbus/3.0.6-2+deb9u1build0.18.04.1 . Upgrade libmodbus to mitigate security risks impacting Ubuntu 18.04 and avert possible system failures.. libmodbus, Ubuntu advisory, denial of service, security update. . LinuxSecurity.com Team
Two issues have been found in libmodbus, a library for the Modbus protocol. Both issues are related to out of bound reads, which could result in a . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2825-1
Addresses CVE-2019-14462 and CVE-2019-14463. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-355f6e10c1 2019-08-25 03:02:58.350184 --------------------------------------------------------------------------------Name : libmodbus Product : Fedora 29 Version : 3.0.8 Release : 1.fc29 URL : Summary : A Modbus library Description : libmodbus is a C library designed to provide a fast and robust implementation of the Modbus protocol. It runs on Linux, Mac OS X, FreeBSD, QNX and Windows. This package contains the libmodbus shared library. --------------------------------------------------------------------------------Update Information: Addresses CVE-2019-14462 and CVE-2019-14463 --------------------------------------------------------------------------------ChangeLog: * Fri Aug 16 2019 Eric Sandeen - 3.0.8-1 - New upstream release - Addresses CVE-2019-14462 and CVE-2019-14463 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-355f6e10c1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Addresses CVE-2019-14462 and CVE-2019-14463. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-4942e01cdc 2019-08-25 00:56:58.831376 --------------------------------------------------------------------------------Name : libmodbus Product : Fedora 30 Version : 3.0.8 Release : 1.fc30 URL : Summary : A Modbus library Description : libmodbus is a C library designed to provide a fast and robust implementation of the Modbus protocol. It runs on Linux, Mac OS X, FreeBSD, QNX and Windows. This package contains the libmodbus shared library. --------------------------------------------------------------------------------Update Information: Addresses CVE-2019-14462 and CVE-2019-14463 --------------------------------------------------------------------------------ChangeLog: * Fri Aug 16 2019 Eric Sandeen - 3.0.8-1 - New upstream release - Addresses CVE-2019-14462 and CVE-2019-14463 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-4942e01cdc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
fix remote buffer overflow vulnerability on write requests. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-ae14784e4e 2016-03-09 20:10:53.638820 -------------------------------------------------------------------------------- Name : libmodbus Product : Fedora 23 Version : 3.0.6 Release : 1.fc23 URL : Summary : A Modbus library Description : libmodbus is a C library designed to provide a fast and robust implementation of the Modbus protocol. It runs on Linux, Mac OS X, FreeBSD, QNX and Windows. This package contains the libmodbus shared library. -------------------------------------------------------------------------------- Update Information: fix remote buffer overflow vulnerability on write requests -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libmodbus' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.