Vulnerability Description
SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon an attempt to parse a large or infinite file (such as a block or character device).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Waycrate | Swhkd | 1.1.5 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2022/04/14/1PatchThird Party Advisory
- https://github.com/waycrate/swhkd/commit/b4e6dc76f4845ab03104187a42ac6d1bbc1e002PatchThird Party Advisory
- https://github.com/waycrate/swhkd/releasesRelease Notes
- http://www.openwall.com/lists/oss-security/2022/04/14/1PatchThird Party Advisory
- https://github.com/waycrate/swhkd/commit/b4e6dc76f4845ab03104187a42ac6d1bbc1e002PatchThird Party Advisory
- https://github.com/waycrate/swhkd/releasesRelease Notes
FAQ
What is CVE-2022-27819?
CVE-2022-27819 is a vulnerability with a CVSS score of 5.3 (MEDIUM). SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon an attempt to parse a large or infinite file (such...
How severe is CVE-2022-27819?
CVE-2022-27819 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-27819?
Check the references section above for vendor advisories and patch information. Affected products include: Waycrate Swhkd.