Skip to main content

Use of Externally-Controlled Format String

CVE-2022-4639

Severity High
Score 9.8/10

Summary

A vulnerability, which was classified as critical, has been found in sslh. This issue affects the function "hexdump" of the file "probe.c" of the component Packet Dumping Handler. The manipulation of the argument "msg_info" leads to format string. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-134 - Use of Externally-Controlled Format String

The software uses a function that accepts a format string as an argument, but the format string originates from an external source.

Advisory Timeline

  • Published