cbcvebase.
CVE-2022-0904
published 2022-03-10

CVE-2022-0904: A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document.

Affected

8 ranges
VendorProductVersion rangeFixed in
mattermostmattermost>= 5.37 < 5.37.85.37.8
mattermostmattermost>= 6.1 < 6.1.36.1.3
mattermostmattermost>= 6.2 < 6.2.36.2.3
mattermostmattermost>= 6.3 < 6.3.36.3.3
mattermostmattermost_server>= 5.0.0 < 5.37.85.37.8
mattermostmattermost_server>= 6.0.0 < 6.1.36.1.3
mattermostmattermost_server>= 6.2.0 < 6.2.36.2.3
mattermostmattermost_server>= 6.3.0 < 6.3.36.3.3