CVE-2022-0904: Stack overflow in document extractor in Mattermost
Published Mar 9, 2022
·Updated
A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document.
Affected Software
4 affected components
Mattermost Mattermost Server>=5.0.0<5.37.8
Mattermost Mattermost Server>=6.0.0<6.1.3
Mattermost Mattermost Server>=6.2.0<6.2.3
Mattermost Mattermost Server>=6.3.0<6.3.3
Remediation
Information
Update the Mattermost version to v6.3.3, 6.2.3, 6.1.3, or 5.37.8, depending on the minor version being run
Event History
Mar 9, 2022
CVE Published
via MITRE·03:21 PM
Data Sourced
via MITRE·03:21 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-0904?
CVE-2022-0904 is a stack overflow bug in the document extractor in Mattermost Server versions up to and including 6.3.2.
2
How can an attacker exploit CVE-2022-0904?
An attacker can exploit CVE-2022-0904 by submitting a maliciously crafted Apple Pages document, which will crash the Mattermost Server.
3
Which versions of Mattermost Server are affected by CVE-2022-0904?
Mattermost Server versions up to and including 6.3.2 are affected by CVE-2022-0904.
4
What is the severity of CVE-2022-0904?
CVE-2022-0904 has a severity rating of 6.5 (medium).
5
How can I fix CVE-2022-0904?
To fix CVE-2022-0904, update your Mattermost Server to version 6.3.3 or newer.