Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 8: MGASA-2022-0319 Critical Update for Connman Exploits

mageia
Calendar Grey September 7, 2022
Dist Mageia Esm H88
Revised connman bundles in Mageia resolve severe security vulnerabilities linked to buffer overflows and unauthorized code execution.
In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code

Summary

In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code. (CVE-2022-32292)
In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution. (CVE-2022-32293)

References

- https://bugs.mageia.org/show_bug.cgi?id=30698

-

- https://www.cve.org/CVERecord?id=CVE-2022-32292

- https://www.cve.org/CVERecord?id=CVE-2022-32293

Resolution

SRPMS

- 8/core/connman-1.38-2.3.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 07 Sep 2022
URL: https://advisories.mageia.org/MGASA-2022-0319.html
Type: security
CVE: CVE-2022-32292, CVE-2022-32293

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here