CVE-2022-4639
MEDIUM
5,6
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: low
Description
AI Translation Available
A vulnerability, which was classified as critical, has been found in sslh. This issue affects the function hexdump of the file probe.c of the component Packet Dumping Handler. The manipulation of the argument msg_info leads to format string. The attack may be initiated remotely. The name of the patch is b19f8a6046b080e4c2e28354a58556bb26040c6f. It is recommended to apply a patch to fix this issue. The identifier VDB-216497 was assigned to this vulnerability.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0018
Percentile
0,4th
Updated
EPSS Score Trend (Last 90 Days)
119
Improper Restriction of Operations within the Bounds of a Memory Buffer
StableCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Modify Memory
Read Memory
Dos: Crash, Exit, Or Restart
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Applicable Platforms
Languages:
Assembly, C, C++, Memory-Unsafe
134
Use of Externally-Controlled Format String
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Potential Impacts:
Read Memory
Modify Memory
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages:
C, C++, Not Language-Specific, Perl
Application
Sslh by Sslh Project
CPE Identifier
View Detailed Analysis
cpe:2.3:a:sslh_project:sslh:2.0:rc1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/yrutschle/sslh/commit/b19f8a6046b080e4c2e28354a58556bb26040c…
https://github.com/yrutschle/sslh/pull/353
https://vuldb.com/?id.216497
https://github.com/yrutschle/sslh/commit/b19f8a6046b080e4c2e28354a58556bb26040c…
https://github.com/yrutschle/sslh/pull/353
https://vuldb.com/?id.216497