CVE-2022-2301

NameCVE-2022-2301
DescriptionBuffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chafa (PTS)buster1.0.1-2vulnerable
bullseye1.6.0-1vulnerable
bookworm1.12.4-1fixed
sid, trixie1.14.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chafasource(unstable)1.10.3-1unimportant

Notes

https://huntr.dev/bounties/f6b9114b-671d-4948-b946-ffe5c9aeb816/
https://github.com/hpjansson/chafa/commit/56fabfa18a6880b4cb66047fa6557920078048d9 (1.12.0)
https://github.com/hpjansson/chafa/commit/a52325294cc018d4fa9a7f29668faea24362b94c (1.10.3)
Crash in CLI tool, no security impact

Search for package or bug name: Reporting problems