CVE-2022-32293: Use After Free
In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-32293?
CVE-2022-32293 is a vulnerability in ConnMan through 1.41 that could allow a man-in-the-middle attack against a WISPR HTTP query, leading to crashes or code execution.
How severe is CVE-2022-32293?
CVE-2022-32293 has a severity rating of 8.1 (high).
Which software versions are affected by CVE-2022-32293?
The versions of ConnMan affected by CVE-2022-32293 include: 1.36-2.1~deb10u5, 1.36-2.2+deb11u2, and 1.41-3.
Is there a fix available for CVE-2022-32293?
Yes, the following fixed versions are available: 1.36-2.1~deb10u2 for debian/connman, 1.35-6ubuntu0.1~ for ubuntu/connman (bionic), 1.36-2ubuntu0.1 for ubuntu/connman (focal), and 1.36-2.3ubuntu0.1 for ubuntu/connman (jammy).
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-32293?
The CWE ID for CVE-2022-32293 is CWE-416.