CVE-2022-23219
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
Affected (11)
Products: Gnu: Glibc · Oracle: Communications Cloud Native Core Binding Support Function, Communications Cloud Native Core Network Function Cloud Native Environment, Communications Cloud Native Core Network Repository Function, Communications Cloud Native Core Security Edge Protection Proxy, Communications Cloud Native Core Unified Data Repository, Enterprise Operations Monitor · Debian: Debian Linux
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 22.1.3 | |
| Version 22.1.0 | |
| Version 22.1.2 | |
| Version 22.1.1 | |
| Version 22.2.0 | |
| Version 4.3 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
References (8)
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
ExploitIssue TrackingThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.