CVE-2022-23097: Critical severity connman vulnerability
An issue was discovered in the DNS proxy in Connman through 1.40. forwarddnsreply mishandles a strnlen call, leading to an out-of-bounds read.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23097?
CVE-2022-23097 is an issue discovered in the DNS proxy in Connman through 1.40, where forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read.
How does CVE-2022-23097 impact Connman?
CVE-2022-23097 could allow an attacker to cause an out-of-bounds read in the DNS proxy of Connman, potentially leading to information disclosure or denial of service.
Which versions of Connman are affected by CVE-2022-23097?
Connman versions 1.36-2.1~deb10u5, 1.36-2.2+deb11u1, 1.36-2.2+deb11u2, and 1.41-3 are affected by CVE-2022-23097.
How can I fix CVE-2022-23097?
To fix CVE-2022-23097, upgrade to Connman version 1.36-2.3ubuntu0.1 or higher, or apply the appropriate security patch provided by your Linux distribution.
Where can I find more information about CVE-2022-23097?
You can find more information about CVE-2022-23097 on the Git repository of Connman and the advisory links provided.