PT-2022-27847 · Sslh · Sslh
Jubalh
·
Published
2022-12-21
·
Updated
2022-12-28
·
CVE-2022-4639
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
sslh (affected versions not specified)
Description
A critical issue has been found in the function
hexdump of the file probe.c of the component Packet Dumping Handler. The manipulation of the argument msg info leads to a format string issue. The attack may be initiated remotely.Recommendations
To fix this issue, it is recommended to apply a patch. Specifically, the patch with the name
b19f8a6046b080e4c2e28354a58556bb26040c6f should be applied. As a temporary workaround, consider disabling the hexdump function until a patch is available. Restrict access to the vulnerable probe.c file to minimize the risk of exploitation. Avoid using the argument msg info in the affected component until the issue is resolved.Fix
Use of Externally-Controlled Format String
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sslh