CVE-2022-40320: High severity Libconfuse Project Libconfuse vulnerability
Published Sep 9, 2022
·Updated
cfgtildeexpand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.
Affected Software
4 affected components
Libconfuse Project Libconfuse=3.3
fedoraproject fedora=35
fedoraproject fedora=36
fedoraproject fedora=37
Remediation
Patch Available
Event History
Sep 9, 2022
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-40320?
CVE-2022-40320 is a vulnerability in libConfuse 3.3 that allows a heap-based buffer over-read in cfg_tilde_expand function.
2
What is the severity of CVE-2022-40320?
The severity of CVE-2022-40320 is high with a severity value of 8.8.
3
Which software is affected by CVE-2022-40320?
The software affected by CVE-2022-40320 includes libConfuse 3.3, Fedoraproject Fedora 35, Fedoraproject Fedora 36, and Fedoraproject Fedora 37.
4
How can I fix CVE-2022-40320?
To fix CVE-2022-40320, it is recommended to update to a patched version of libConfuse or apply available security patches for the affected software.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-40320?
CVE-2022-40320 is associated with CWE-125, which refers to Out-of-bounds Read vulnerability.