PT-2022-3802 · Swhkd · Swhkd

Matthias Gerstner

·

Published

2022-04-06

·

Updated

2023-08-08

·

CVE-2022-27814

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SWHKD version 1.1.5
Description The issue is related to a lack of proper access control in the SWHKD implementation of the Wayland display server protocol, specifically when handling files with the -c option. This can allow an attacker to perform arbitrary file-existence tests, potentially leading to unauthorized access to protected information.
Recommendations For SWHKD version 1.1.5, consider disabling the -c option as a temporary workaround until a patch is available. Restrict access to sensitive files and information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Side Channel Attack

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2022-04597
CVE-2022-27814
GHSA-X446-3XHQ-5XFP

Affected Products

Swhkd