Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2022-35737 |
CWE-ID | CWE-129 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #1 is available. |
Vulnerable software Subscribe |
cflinuxfs3 Other software / Other software solutions |
Vendor | Cloud Foundry Foundation |
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU67414
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-35737
CWE-ID:
CWE-129 - Improper Validation of Array Index
Exploit availability: Yes
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when handling an overly large input passed as argument to a C API. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Install update from vendor's website.
Vulnerable software versionscflinuxfs3: before 0.332.0
http://github.com/cloudfoundry/cflinuxfs3/releases/tag/0.332.0
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?