cbcvebase.
CVE-2022-23098
published 2022-01-28

CVE-2022-23098: An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.

Affected

12 ranges
VendorProductVersion rangeFixed in
connmanconnman>= 0 < 1.36-2.2+deb11u11.36-2.2+deb11u1
connmanconnman>= 0 < 1.36-2.41.36-2.4
connmanconnman>= 0 < 1.36-2.41.36-2.4
connmanconnman>= 0 < 1.36-2.41.36-2.4
connmanconnman>= 0 < 1.36-2ubuntu0.11.36-2ubuntu0.1
connmanconnman>= 0 < 1.36-2.3ubuntu0.11.36-2.3ubuntu0.1
connmanconnman>= 0 < 1.21-1.2+deb8u1ubuntu0.1~esm11.21-1.2+deb8u1ubuntu0.1~esm1
connmanconnman>= 0 < 1.35-6ubuntu0.1~esm11.35-6ubuntu0.1~esm1
debianconnman< connman 1.36-2.4 (bookworm)connman 1.36-2.4 (bookworm)
debiandebian_linux
debiandebian_linux
intelconnman<= 1.40

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH