CVE-2022-32292: Buffer Overflow
In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in receiveddata to execute code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-32292.
What is the title of the vulnerability?
The title of the vulnerability is 'In ConnMan through 1.41 remote attackers able to send HTTP requests to the gweb component are able to...'
What is the description of the vulnerability?
The description of the vulnerability is 'In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.'
What software versions are affected by this vulnerability?
The affected software versions are 1.36-2.1~deb10u5, 1.36-2.2+deb11u1, 1.36-2.2+deb11u2, and 1.41-3.
What is the fix for this vulnerability?
The fix for this vulnerability depends on the affected software package. Please refer to the provided references for the specific remedy.
What are the references for this vulnerability?
The references for this vulnerability are 'https://lore.kernel.org/connman/20220801080043.4861-5-wagi@monom.org/', 'https://bugzilla.suse.com/show_bug.cgi?id=1200189', and 'https://www.debian.org/security/2022/dsa-5231'.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-119.