CVE-2022-23462
Versions 1.4.15 and prior contain a stack buffer overflow vulnerability that allows for Denial of Service (DOS) when it parses scientific notation numbers present in JSON.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IOWOW is a C utility library and persistent key/value storage engine. Versions 1.4.15 and prior contain a stack buffer overflow vulnerability that allows for Denial of Service (DOS) when it parses scientific notation numbers present in JSON. A patch for this issue is available at commit a79d31e4cff1d5a08f665574b29fd885897a28fd in the `master` branch of the repository. There are no workarounds other than applying the patch.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120, CWE-121, CWE-787
- Affected
- softmotions/iowow
- Source
- security-advisories@github.com
References
- https://github.com/Softmotions/iowow/commit/a79d31e4cff1d5a08f665574b29fd885897a28fdPatch, Third Party Advisory
- https://securitylab.github.com/advisories/GHSL-2022-066_iowow/Exploit, Third Party Advisory
- https://github.com/Softmotions/iowow/commit/a79d31e4cff1d5a08f665574b29fd885897a28fdPatch, Third Party Advisory
- https://securitylab.github.com/advisories/GHSL-2022-066_iowow/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.