PT-2022-16029 · Yauaa · Yauaa
Nielsbasjes
·
Published
2022-12-08
·
Updated
2022-12-12
·
CVE-2022-23496
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Yet Another UserAgent Analyzer (Yauaa) versions 7.0.0 through 7.8.x
Description
The Yauaa library can throw an ArrayIndexOutOfBoundsException when analyzing useragent strings, potentially causing applications to crash if the exception is uncaught. This issue affects applications using the Client Hints analysis feature introduced with version 7.0.0. Applications not using this feature are not affected.
Recommendations
For versions 7.0.0 through 7.8.x, upgrade to version 7.9.0 to resolve the issue.
For users unable to upgrade, catch and discard any ArrayIndexOutOfBoundsException thrown by the Yauaa library as a temporary workaround.
Exploit
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yauaa