cbcvebase.
CVE-2022-3715
published 2023-01-05

CVE-2022-3715: A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianbash< bash 5.2-1 (bookworm)bash 5.2-1 (bookworm)
glance_projectglance>= 0 < 3.0.93.0.9
gnubash
gnubash>= 0 < 5.2-15.2-1
gnubash>= 0 < 5.2-15.2-1
gnubash>= 0 < 5.2-15.2-1
gnubash>= 5.1 < 5.1.85.1.8
msrccm1_bash_4.4.23-1_on_cbl_mariner_1.0
redhatenterprise_linux

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa6.5MEDIUM
osv7.8HIGH
cisa5.5MEDIUM