CVE-2022-45693Out-of-bounds Write in Project Jettison

CWE-787Out-of-bounds Write10 documents7 sources
Severity
7.5HIGHNVD
EPSS
0.1%
top 65.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13
Latest updateJul 15

Description

Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

debiandebian/libjettison-java< libjettison-java 1.5.3-1 (bookworm)

Also affects: Debian Linux 10.0, 11.0

🔴Vulnerability Details

3
OSV
CVE-2022-45693: Jettison before v12022-12-13
OSV
Jettison Out-of-bounds Write vulnerability2022-12-13
GHSA
Jettison Out-of-bounds Write vulnerability2022-12-13

📋Vendor Advisories

6
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security (Jettison) — CVE-2022-456932025-07-15
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Jettison) — CVE-2022-456932023-07-15
Ubuntu
Jettison vulnerabilities2023-06-19
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Jettison) — CVE-2022-456932023-04-15
Red Hat
jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos2022-12-13