CVE-2022-23098: High severity connman vulnerability
Published Jan 28, 2022
·Updated
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.
Affected Software
8 affected componentsFixes available
ubuntu/connman<1.21-1.2+
1.21-1.2+
ubuntu/connman<1.35-6ubuntu0.1~
1.35-6ubuntu0.1~
ubuntu/connman<1.36-2ubuntu0.1
1.36-2ubuntu0.1
ubuntu/connman<1.36-2.3ubuntu0.1
1.36-2.3ubuntu0.1
debian/connman<=1.36-2.1~deb10u2
1.36-2.1~deb10u51.36-2.2+deb11u21.41-31.42-5
Intel Connman<=1.40
Debian Debian Linux=9.0
Debian Debian Linux=11.0
Event History
Jan 28, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:07 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Connman?
The vulnerability ID for this issue in Connman is CVE-2022-23098.
2
What is the severity of CVE-2022-23098?
The severity of CVE-2022-23098 is high with a CVSS score of 7.5.
3
What is the affected software in this vulnerability?
The affected software in this vulnerability is Connman.
4
How can I fix CVE-2022-23098?
To fix CVE-2022-23098, you should update Connman to version 1.41-3 or apply the recommended patches provided by the respective software vendors.
5
Where can I find more information about CVE-2022-23098?
You can find more information about CVE-2022-23098 at the following references: [link1], [link2], [link3].