PT-2022-4871 · Openwrt · Openwrt
Published
2022-09-19
·
Updated
2023-05-24
·
CVE-2022-38333
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Openwrt versions prior to 21.02.3
Openwrt version 22.03.0-rc6
Description
The issue is related to a buffer overflow vulnerability in the
header value function, which allows attackers to access sensitive information via a crafted HTTP request. This can be exploited by sending a specially formed HTTP request, potentially giving a remote attacker access to protected information.Recommendations
For Openwrt versions prior to 21.02.3, update to version 21.02.3 or later.
For Openwrt version 22.03.0-rc6, consider disabling the
header value function until a patch is available.
As a temporary workaround, restrict access to the vulnerable header value function to minimize the risk of exploitation.Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openwrt