OSV-2022-150
Dashboard / Vulnerabilities / OSV-2022-150
OSV-2022-150
Published: 14 Feb 2022Last Modified: 25 Sept 2026
Summary: Heap-buffer-overflow in coap_split_uri_sub
Details: OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=44611 Crash type: Heap-buffer-overflow READ 1 Crash state: coap_split_uri_sub coap_get_uri_path
Affected packages
Package
Name: libcoap
Purl: pkg:generic/libcoap
Affected ranges
Type: GIT
Events:
Introduced- 6504b667d38012efa81087bf4cc960128f4dc2d4
Fixed -None
Affected versions
v4.3.1
v4.3.1-rc1
v4.3.1-rc2
v4.3.2-rc1
v4.3.2-rc2
v4.3.2
v4.3.3
v4.3.4
v4.3.4a
v4.3.5-rc1
v4.3.5-rc2
v4.3.5-rc3
v4.3.5
v4.3.5a
v4.3.5b
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
