Description
In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3105-1 | connman security update |
Debian DLA |
DLA-3144-1 | connman security update |
Debian DSA |
DSA-5231-1 | connman security update |
Ubuntu USN |
USN-6236-1 | ConnMan vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T07:39:50.262Z
Reserved: 2022-06-05T00:00:00.000Z
Link: CVE-2022-32293
No data.
Status : Modified
Published: 2022-08-03T14:15:08.667
Modified: 2024-11-21T07:06:07.250
Link: CVE-2022-32293
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Ubuntu USN