PT-2022-16029 · Yauaa · Yauaa

Nielsbasjes

·

Published

2022-12-08

·

Updated

2022-12-12

·

CVE-2022-23496

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Yet Another UserAgent Analyzer (Yauaa) versions 7.0.0 through 7.8.x
Description The Yauaa library can throw an ArrayIndexOutOfBoundsException when analyzing useragent strings, potentially causing applications to crash if the exception is uncaught. This issue affects applications using the Client Hints analysis feature introduced with version 7.0.0. Applications not using this feature are not affected.
Recommendations For versions 7.0.0 through 7.8.x, upgrade to version 7.9.0 to resolve the issue. For users unable to upgrade, catch and discard any ArrayIndexOutOfBoundsException thrown by the Yauaa library as a temporary workaround.

Exploit

Fix

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23496
GHSA-C4PM-63CG-9J7H

Affected Products

Yauaa