wire-avs provides Audio, Visual, and Signaling (AVS) functionality sure the secure messaging software Wire. Prior to versions 9.2.22 and 9.3.5, a remote format string vulnerability could potentially allow an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs 9.2.22 & 9.3.5 and is already included on all Wire products. No known workarounds are available.
{
"cwe_ids": [
"CWE-134"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/48xxx/CVE-2023-48221.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-48221.json"
[
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/wireapp/wire-avs/commit/0aeb00292e2c21161dfe0abb43464d4c73152681",
"digest": {
"line_hashes": [
"122746583417084871728688984422911930131",
"215000251740698008057616661646412624494",
"282003704325653094155278138383421371658",
"288898036967538360780169907322905309768"
],
"threshold": 0.9
},
"id": "CVE-2023-48221-26b2d296",
"deprecated": false,
"target": {
"file": "src/sdp/bundle.c"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/wireapp/wire-avs/commit/0aeb00292e2c21161dfe0abb43464d4c73152681",
"digest": {
"function_hash": "238999916680917770632223221160041664663",
"length": 1125.0
},
"id": "CVE-2023-48221-8e98474f",
"deprecated": false,
"target": {
"file": "src/sdp/bundle.c",
"function": "bundle_update"
}
}
]