PT-2022-2658 · Connman+5 · Connman+5

Matthias Gerstner

·

Published

2022-01-28

·

Updated

2024-06-15

·

CVE-2022-23097

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Connman versions 1.40 and earlier
Description An issue was discovered in the DNS proxy in Connman, where the forward dns reply function mishandles a strnlen call, leading to an out-of-bounds read. This could allow a remote attacker to access confidential information or cause a denial of service.
Recommendations For Connman versions 1.40 and earlier, as a temporary workaround, consider disabling the forward dns reply function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1202
ALT-PU-2022-2324
ALT-PU-2022-2468
BDU:2022-03146
CVE-2022-23097
DLA-2915-1
DLA-3144-1
DSA-5231-1
MGASA-2022-0045
OPENSUSE-SU-2022_0056-1
OPENSUSE-SU-2024:11792-1
USN-6236-1

Affected Products

Alt Linux
Astra Linux
Connman
Linuxmint
Suse
Ubuntu