VulnerabilityModified
CVE-2022-22820
Due to the lack of media file checks before rendering, it was possible for an attacker to cause abnormal CPU consumption for message recipient by sending specially crafted gif image in LINE for Windows before 7.4.
MEDIUM 5.5EPSS 0.84%
Does this matter?
Lower severity and a low EPSS score (0.84%). Track it; it rarely justifies an emergency change on its own.
Description
Due to the lack of media file checks before rendering, it was possible for an attacker to cause abnormal CPU consumption for message recipient by sending specially crafted gif image in LINE for Windows before 7.4.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 0.84% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- linecorp/line
- Source
- dl_cve@linecorp.com
References
- https://hackerone.com/reports/1357400Permissions Required
- https://hackerone.com/reports/1357400Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.