CVE-2022-32096: Buffer Overflow
Published Jul 13, 2022
·Updated
Rhonabwy before v1.1.5 was discovered to contain a buffer overflow via the component rjweaesgcmkeyunwrap. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted JWE token.
Affected Software
1 affected component
Rhonabwy Project Rhonabwy<1.1.5
Remediation
Event History
Jul 13, 2022
CVE Published
via MITRE·03:42 PM
Data Sourced
via MITRE·03:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-32096?
CVE-2022-32096 is classified as a high severity vulnerability due to its potential to cause a Denial of Service.
2
How do I fix CVE-2022-32096?
To fix CVE-2022-32096, upgrade to Rhonabwy version 1.1.5 or later to mitigate the buffer overflow vulnerability.
3
What component is affected in CVE-2022-32096?
CVE-2022-32096 affects the component r_jwe_aesgcm_key_unwrap in Rhonabwy.
4
What type of attack can exploit CVE-2022-32096?
CVE-2022-32096 can be exploited to perform a Denial of Service (DoS) attack via a crafted JWE token.
5
Which versions of Rhonabwy are affected by CVE-2022-32096?
CVE-2022-32096 affects all versions of Rhonabwy before 1.1.5.