CVE-2022-23096: Critical severity connman vulnerability
Published Jan 28, 2022
·Updated
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient Header Data, leading to an out-of-bounds read.
Affected Software
9 affected componentsFixes available
debian/connman<=1.36-2.3, <=1.36-2.1~deb10u1, <=1.36-2.1~deb10u2, <=1.36-2.2
1.36-2.41.36-2.2+deb11u1
debian/connman<=1.36-2.1~deb10u2
1.36-2.1~deb10u51.36-2.2+deb11u21.41-31.42-5
ubuntu/connman<1.35-6ubuntu0.1~
1.35-6ubuntu0.1~
ubuntu/connman<1.21-1.2+
1.21-1.2+
ubuntu/connman<1.36-2.3ubuntu0.1
1.36-2.3ubuntu0.1
ubuntu/connman<1.36-2ubuntu0.1
1.36-2ubuntu0.1
Intel Connman<=1.40
Debian Debian Linux=9.0
Debian Debian Linux=11.0
Event History
Jan 28, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:07 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-23096.
2
What software is affected by this vulnerability?
Connman versions 1.21-1.2+ through 1.40 are affected by this vulnerability.
3
What is the severity of CVE-2022-23096?
The severity of CVE-2022-23096 is not mentioned in the provided information.
4
How can I mitigate the vulnerability in Connman?
To mitigate the vulnerability in Connman, update to version 1.41-3 or the latest available version.
5
Where can I find more information about CVE-2022-23096?
You can find more information about CVE-2022-23096 in the provided references: [Link1], [Link2], [Link3].