Out-of-Bounds Read Vulnerability in Connman DNS Proxy
CVE-2022-23096
9.1CRITICAL
Summary
A critical issue has been discovered in the DNS proxy component of Connman, where the implementation of the TCP server reply fails to validate the presence of sufficient header data. This oversight allows an out-of-bounds read, which could lead to potential information disclosure or further exploitation of the affected systems. Users are advised to apply the latest updates to ensure network security.
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved