HIGH
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE)
Published Sep 8, 2022
7.5
HIGHCVSS 3.1
EPSS 0.68%
Description
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43578 Advisory
- https://github.com/Samsung/TizenRT/blob/f8f776dd183246ad8890422c1ee5e8f33ab2aaaf/external/curl/vtls/cyassl.c#L545 x_refsource_MISCThird Party Advisory
- https://github.com/Samsung/TizenRT/issues/5626 x_refsource_MISCIssue TrackingThird Party Advisory
- https://www.openssl.org/docs/man1.1.1/man3/SSL_get_peer_certificate.html x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43578 | Advisory | |
| https://github.com/Samsung/TizenRT/blob/f8f776dd183246ad8890422c1ee5e8f33ab2aaaf/external/curl/vtls/cyassl.c#L545 | x_refsource_MISCThird Party Advisory | |
| https://github.com/Samsung/TizenRT/issues/5626 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://www.openssl.org/docs/man1.1.1/man3/SSL_get_peer_certificate.html | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 8, 2022
Updated Aug 3, 2024
Reserved Sep 8, 2022
Link CVE-2022-40281
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data