libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language) configuration in use.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-45623 libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language) configuration in use.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 03 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Libvmod Digest
Libvmod Digest libvmod Digest
CPEs cpe:2.3:a:libvmod_digest:libvmod_digest:*:*:*:*:*:*:*:*
Vendors & Products Libvmod Digest
Libvmod Digest libvmod Digest
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-03T14:09:51.999Z

Reserved: 2023-08-23T00:00:00

Link: CVE-2023-41104

cve-icon Vulnrichment

Updated: 2024-08-02T18:54:02.970Z

cve-icon NVD

Status : Modified

Published: 2023-08-23T07:15:08.417

Modified: 2024-11-21T08:20:35.543

Link: CVE-2023-41104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.