CVE-2022-34299
published 2022-06-23CVE-2022-34299: There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
PriorityP335high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
1.17%
64.0th percentile
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dwarfutils | < dwarfutils 1:0.11.1-1 (forky) | dwarfutils 1:0.11.1-1 (forky) |
| libdwarf_project | libdwarf | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3j8p-q74h-4pxp: There is a heap-based buffer over-read in libdwarf 0
ghsa_unreviewed·2022-06-24
CVE-2022-34299 [HIGH] CWE-125 GHSA-3j8p-q74h-4pxp: There is a heap-based buffer over-read in libdwarf 0
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
OSV
CVE-2022-34299: There is a heap-based buffer over-read in libdwarf 0
osv·2022-06-23·CVSS 8.1
CVE-2022-34299 [HIGH] CVE-2022-34299: There is a heap-based buffer over-read in libdwarf 0
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
Red Hat
libdwarf: heap buffer over-read in dwarf_global_formref_b() in dwarf_form.c
vendor_redhat·2022-06-23·CVSS 8.1
CVE-2022-34299 [HIGH] CWE-126 libdwarf: heap buffer over-read in dwarf_global_formref_b() in dwarf_form.c
libdwarf: heap buffer over-read in dwarf_global_formref_b() in dwarf_form.c
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
A buffer-overflow vulnerability was found in libdwarf's dwarf_global_formref_b() function in dwarf_form.c. A carefully crafted `.debug_info` causes libdwarf to read outside a buffer containing a Dwarf_Sig8 symbolic reference. This issue can cause a segmentation violation or other major error, terminating the calling application and resulting in a denial of service.
Statement: The bug has been present since DWARF4 when DW_FORM_ref_sig8 was added to libdwarf. But, in our code-base, we cannot handle this functionality yet. There is no presence of vulnerable code in our code-base. Hence, versions of libdwarf sh
Debian
CVE-2022-34299: dwarfutils - There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related ...
vendor_debian·2022·CVSS 8.1
CVE-2022-34299 [HIGH] CVE-2022-34299: dwarfutils - There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related ...
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:0.11.1-1)
sid: resolved (fixed in 1:0.11.1-1)
trixie: resolved (fixed in 1:0.11.1-1)
Suricata
ET WEB_SPECIFIC_APPS Monsta FTP Server Side Request Forgery Attempt (CVE-2022-31827)
suricata·2025-11-07·CVSS 9.1
CVE-2022-31827 [CRITICAL] ET WEB_SPECIFIC_APPS Monsta FTP Server Side Request Forgery Attempt (CVE-2022-31827)
ET WEB_SPECIFIC_APPS Monsta FTP Server Side Request Forgery Attempt (CVE-2022-31827)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Monsta FTP Server Side Request Forgery Attempt (CVE-2022-31827)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/application/api/api.php"; http.request_body; content:"|22|actionName|22 3a 22|fetchRemoteFile|22|"; fast_pattern; content:"|22|source|22 3a 22|http|3a 2f 2f|"; reference:url,labs.watchtowr.com/whats-that-coming-over-the-hill-monsta-ftp-remote-code-execution-cve-2025-34299/; reference:cve,2022-31827; classtype:web-application-attack; sid:2065694; rev:1; metadata:affected_product Monsta_FTP, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_11_07, cve CVE_2022_31827, deploymen
No public exploits indexed.
No writeups or analysis indexed.
2022-06-23
Published