First published: Wed Mar 09 2022(Updated: )
A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | >=5.0.0<5.37.8 | |
Mattermost Mattermost Server | >=6.0.0<6.1.3 | |
Mattermost Mattermost Server | >=6.2.0<6.2.3 | |
Mattermost Mattermost Server | >=6.3.0<6.3.3 |
Update the Mattermost version to v6.3.3, 6.2.3, 6.1.3, or 5.37.8, depending on the minor version being run
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0904 is a stack overflow bug in the document extractor in Mattermost Server versions up to and including 6.3.2.
An attacker can exploit CVE-2022-0904 by submitting a maliciously crafted Apple Pages document, which will crash the Mattermost Server.
Mattermost Server versions up to and including 6.3.2 are affected by CVE-2022-0904.
CVE-2022-0904 has a severity rating of 6.5 (medium).
To fix CVE-2022-0904, update your Mattermost Server to version 6.3.3 or newer.