PT-2022-4871 · Openwrt · Openwrt

CVE-2022-38333

·

Published

2022-09-19

·

Updated

2023-05-24

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Openwrt versions prior to 21.02.3 Openwrt version 22.03.0-rc6
Description The issue is related to a buffer overflow vulnerability in the header value function, which allows attackers to access sensitive information via a crafted HTTP request. This can be exploited by sending a specially formed HTTP request, potentially giving a remote attacker access to protected information.
Recommendations For Openwrt versions prior to 21.02.3, update to version 21.02.3 or later. For Openwrt version 22.03.0-rc6, consider disabling the header value function until a patch is available. As a temporary workaround, restrict access to the vulnerable header value function to minimize the risk of exploitation.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05995
CVE-2022-38333

Affected Products

Openwrt