CVE-2022-43286: Use After Free
Published Oct 28, 2022
·Updated
Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njsjsonparseiteratorcall at njsjson.c.
Affected Software
1 affected component
F5 Njs=0.7.2
Remediation
Patch Available
Event History
Oct 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-43286?
The severity of CVE-2022-43286 is rated as critical.
2
How does CVE-2022-43286 affect the Nginx NJS software?
CVE-2022-43286 affects Nginx NJS v0.7.2.
3
What is the cause of CVE-2022-43286?
CVE-2022-43286 is caused by an illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c.
4
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2022-43286.
5
Are there any fixes available for CVE-2022-43286?
Yes, fixes for CVE-2022-43286 are available. Please refer to the references for more information.