Headline
CVE-2023-31284: GitHub - illumos/illumos-gate at 16b76d3cb933ff92018a2a75594449010192eacb
illumos illumos-gate before 676abcb has a stack buffer overflow in /dev/net, leading to privilege escalation via a stat on a long file name in /dev/net.
illumos-gate
This is the core illumos source tree.
Building
The illumos build must be run on an illumos-based operating system. See the Building illumos section of our documentation for detailed instructions.
Contributing
Code changes must be reviewed and tested. If you’d like to submit a change for inclusion in the project, please see the Contributing to illumos guide in our documentation.
Community
The illumos community is small but active. We welcome everybody who would like to use the software and participate in the community – whether you’ve decades of experience in systems software, or you’re just getting started; whether you work for a company that uses illumos, or you just find it personally interesting.
Our Community guide includes details about our Mailing Lists and IRC channels.
Code of Conduct
Participation in our community spaces, and in the project in general, are covered by our Code of Conduct. By participating in the project you agree to abide by its terms.
License
Most of the existing code is licensed under the CDDL and we expect new code will generally be under this license as well. Modifications of existing code may not alter the original license terms. Integrations of code from upstream sources that use another open source license are permissible, subject to approval of the advocates.
Related news
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. While the vulnerability is in Oracle Hyperion Financial Reporting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).