First published: Thu Sep 08 2022(Updated: )
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Tizen RT | =1.0-m1 | |
Samsung Tizen RT | =1.1 | |
Samsung Tizen RT | =2.0 | |
Samsung Tizen RT | =3.0-gbm |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40281 is classified as a high severity vulnerability due to the risk of information disclosure.
To address CVE-2022-40281, ensure you update to the latest patched version of Samsung TizenRT that resolves the missing X509_free issue.
CVE-2022-40281 affects Samsung TizenRT versions 1.0-m1, 1.1, 2.0, and 3.0-gbm.
CVE-2022-40281 is characterized as an information disclosure vulnerability.
CVE-2022-40281 can potentially be exploited by an attacker with network access to the affected systems that can initiate SSL connections.