Improper Handling of Length Parameter Inconsistency
CVE-2022-3272
Summary
Improper Handling of Length Parameter Inconsistency in rdiffweb prior to 2.4.8.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- NONE
- HIGH
CWE-130 - Improper Handling of Length Parameter Inconsistency
The software parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.
References
Advisory Timeline
- Published