PT-2022-4809 · Unknown+2 · Libconfuse+2

Kdsjzho

·

Published

2022-09-02

·

Updated

2022-10-28

·

CVE-2022-40320

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libConfuse version 3.3
Description The issue is related to a heap-based buffer over-read in the cfg tilde expand function of the libConfuse library. This can be exploited by a remote attacker using a specially crafted file, potentially leading to a denial of service.
Recommendations For libConfuse version 3.3, consider disabling the cfg tilde expand function as a temporary workaround until a patch is available. Restrict access to the confuse.c file to minimize the risk of exploitation. Avoid using the cfg tilde expand function in configurations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-10925
AZL-34910
BDU:2022-05795
CVE-2022-40320
MGASA-2022-0387
OESA-2022-1928
OPENSUSE-SU-2022_3807-1
OPENSUSE-SU-2024:12324-1
SUSE-SU-2022:3331-1
SUSE-SU-2022:3807-1
SUSE-SU-2022_3331-1
SUSE-SU-2022_3807-1

Affected Products

Red Os
Suse
Libconfuse