CVE-2022-23097 — Out-of-bounds Read in Intel Connman
Severity
9.1CRITICALNVD
EPSS
0.1%
top 73.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 28
Latest updateJul 19
Description
An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2
Affected Packages2 packages
Also affects: Debian Linux 11.0, 9.0