8.8
CVE-2023-48221
- EPSS 0.88%
- Veröffentlicht 20.11.2023 18:15:06
- Zuletzt bearbeitet 21.11.2024 08:31:14
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
wire-avs remote format string vulnerability
wire-avs provides Audio, Visual, and Signaling (AVS) functionality sure the secure messaging software Wire. Prior to versions 9.2.22 and 9.3.5, a remote format string vulnerability could potentially allow an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs 9.2.22 & 9.3.5 and is already included on all Wire products. No known workarounds are available.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wire ≫ Audio, Video, And Signaling Version < 9.2.22
Wire ≫ Audio, Video, And Signaling Version >= 9.3.0 <= 9.3.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.88% | 0.544 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| security-advisories@github.com | 7.3 | 1 | 5.8 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:H
|
CWE-134 Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
https://github.com/wireapp/wire-avs/commit/364c3326a1331a84607bce2e17126306d39150cd
https://github.com/wireapp/wire-avs/security/advisories/GHSA-m4xg-fcr3-w3pq