Vulnerability Database
Blog
FAQ
Docs
CVE-2022-2301
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2022-2301
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2301.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-2301
Related
UBUNTU-CVE-2022-2301
openSUSE-SU-2022:10044-1
openSUSE-SU-2022:10045-1
Published
2022-07-04T11:15:13Z
Modified
2025-01-15T02:15:01.443319Z
Downstream
openSUSE-SU-2022:10044-1
openSUSE-SU-2022:10045-1
Severity
5.5 (Medium)
CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
[none]
Details
Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3.
References
https://huntr.dev/bounties/f6b9114b-671d-4948-b946-ffe5c9aeb816
https://github.com/hpjansson/chafa/commit/56fabfa18a6880b4cb66047fa6557920078048d9
https://security-tracker.debian.org/tracker/CVE-2022-2301
Affected packages
Debian:11
/
chafa
Package
Name
chafa
Purl
pkg:deb/debian/chafa?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Affected versions
1.*
1.6.0-1
1.8.0-1
1.10.0-1
1.10.1-1
1.10.2-1
1.10.3-1~bpo11+1
1.10.3-1
1.12.0-1
1.12.1-1
1.12.3-1~bpo11+1
1.12.3-1
1.12.4-1~bpo11+1
1.12.4-1
1.12.5-1
1.12.5-2
1.12.5-3~hurd.1
1.12.5-3
1.14.0-1
1.14.0-1.1~exp1
1.14.0-1.1
1.14.1-1
1.14.2-1
1.14.4-1
1.14.4-2
1.14.5-1
Ecosystem specific
{ "urgency": "unimportant" }
Debian:12
/
chafa
Package
Name
chafa
Purl
pkg:deb/debian/chafa?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.10.3-1
Ecosystem specific
{ "urgency": "unimportant" }
Debian:13
/
chafa
Package
Name
chafa
Purl
pkg:deb/debian/chafa?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.10.3-1
Ecosystem specific
{ "urgency": "unimportant" }
Git
/
github.com/hpjansson/chafa
Affected ranges
Type
GIT
Repo
https://github.com/hpjansson/chafa
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
56fabfa18a6880b4cb66047fa6557920078048d9
Fixed
56fabfa18a6880b4cb66047fa6557920078048d9
Affected versions
0.*
0.9.0
1.*
1.0.0
1.10.0
1.2.0
1.4.0
1.6.0
1.8.0
CVE-2022-2301 - OSV