Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 5 |
CVE-ID | CVE-2022-24675 CVE-2022-28327 CVE-2022-29526 CVE-2022-21698 CVE-2022-1996 |
CWE-ID | CWE-120 CWE-190 CWE-264 CWE-20 CWE-942 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
Fedora Operating systems & Components / Operating system yubihsm-connector Operating systems & Components / Operating system package or component yggdrasil Operating systems & Components / Operating system package or component xq Operating systems & Components / Operating system package or component wgctrl Operating systems & Components / Operating system package or component weldr-client Operating systems & Components / Operating system package or component webanalyze Operating systems & Components / Operating system package or component vultr-cli Operating systems & Components / Operating system package or component vultr Operating systems & Components / Operating system package or component vgrep Operating systems & Components / Operating system package or component tinygo Operating systems & Components / Operating system package or component tiedot Operating systems & Components / Operating system package or component terrier Operating systems & Components / Operating system package or component sysutil Operating systems & Components / Operating system package or component source-to-image Operating systems & Components / Operating system package or component snowcrash Operating systems & Components / Operating system package or component snapd Operating systems & Components / Operating system package or component shhgit Operating systems & Components / Operating system package or component shellz Operating systems & Components / Operating system package or component runc Operating systems & Components / Operating system package or component reg Operating systems & Components / Operating system package or component powerline-go Operating systems & Components / Operating system package or component podman-tui Operating systems & Components / Operating system package or component ohmybackup Operating systems & Components / Operating system package or component nex Operating systems & Components / Operating system package or component netscanner Operating systems & Components / Operating system package or component nats-server Operating systems & Components / Operating system package or component mqttcli Operating systems & Components / Operating system package or component moby-engine Operating systems & Components / Operating system package or component micro Operating systems & Components / Operating system package or component meshbird Operating systems & Components / Operating system package or component meg Operating systems & Components / Operating system package or component mass3 Operating systems & Components / Operating system package or component manifest-tool Operating systems & Components / Operating system package or component kiln Operating systems & Components / Operating system package or component jid Operating systems & Components / Operating system package or component ignition Operating systems & Components / Operating system package or component hulk Operating systems & Components / Operating system package or component httprobe Operating systems & Components / Operating system package or component httpdump Operating systems & Components / Operating system package or component htmltest Operating systems & Components / Operating system package or component hcloud Operating systems & Components / Operating system package or component hakrevdns Operating systems & Components / Operating system package or component grpcurl Operating systems & Components / Operating system package or component gotags Operating systems & Components / Operating system package or component gopass Operating systems & Components / Operating system package or component google-guest-agent Operating systems & Components / Operating system package or component goloris Operating systems & Components / Operating system package or component golang-x-tools Operating systems & Components / Operating system package or component golang-x-text Operating systems & Components / Operating system package or component golang-x-perf Operating systems & Components / Operating system package or component golang-x-mod Operating systems & Components / Operating system package or component golang-x-build Operating systems & Components / Operating system package or component golang-vbom-util Operating systems & Components / Operating system package or component golang-storj-drpc Operating systems & Components / Operating system package or component golang-sourcegraph-appdash Operating systems & Components / Operating system package or component golang-mvdan-xurls Operating systems & Components / Operating system package or component golang-mvdan-sh-3 Operating systems & Components / Operating system package or component golang-mongodb-mongo-driver Operating systems & Components / Operating system package or component golang-modernc-golex Operating systems & Components / Operating system package or component golang-k8s-sample-controller Operating systems & Components / Operating system package or component golang-k8s-sample-cli-plugin Operating systems & Components / Operating system package or component golang-k8s-sample-apiserver Operating systems & Components / Operating system package or component golang-k8s-pod-security-admission Operating systems & Components / Operating system package or component golang-k8s-kube-openapi Operating systems & Components / Operating system package or component golang-k8s-kube-aggregator Operating systems & Components / Operating system package or component golang-k8s-code-generator Operating systems & Components / Operating system package or component golang-k8s-apiextensions-apiserver Operating systems & Components / Operating system package or component golang-jaytaylor-html2text Operating systems & Components / Operating system package or component golang-honnef-tools Operating systems & Components / Operating system package or component golang-gopkg-src-d-git-4 Operating systems & Components / Operating system package or component golang-gopkg-square-jose-2 Operating systems & Components / Operating system package or component golang-gopkg-neurosnap-sentences-1 Operating systems & Components / Operating system package or component golang-google-protobuf Operating systems & Components / Operating system package or component golang-google-appengine Operating systems & Components / Operating system package or component golang-gitlab-commonmark-linkify Operating systems & Components / Operating system package or component golang-github-xordataexchange-crypt Operating systems & Components / Operating system package or component golang-github-xo-terminfo Operating systems & Components / Operating system package or component golang-github-vmware-govmomi Operating systems & Components / Operating system package or component golang-github-vincent-petithory-dataurl Operating systems & Components / Operating system package or component golang-github-vbatts-tar-split Operating systems & Components / Operating system package or component golang-github-valyala-fasthttp Operating systems & Components / Operating system package or component golang-github-ulikunitz-xz Operating systems & Components / Operating system package or component golang-github-uber-athenadriver Operating systems & Components / Operating system package or component golang-github-u-root-iscsinl Operating systems & Components / Operating system package or component golang-github-twpayne-waypoint Operating systems & Components / Operating system package or component golang-github-twitchtv-twirp Operating systems & Components / Operating system package or component golang-github-tklauser-numcpus Operating systems & Components / Operating system package or component golang-github-tinylib-msgp Operating systems & Components / Operating system package or component golang-github-theupdateframework-notary Operating systems & Components / Operating system package or component golang-github-theoapp-theo-agent Operating systems & Components / Operating system package or component golang-github-temoto-robotstxt Operating systems & Components / Operating system package or component golang-github-tdewolff-minify Operating systems & Components / Operating system package or component golang-github-task Operating systems & Components / Operating system package or component golang-github-spyzhov-ajson Operating systems & Components / Operating system package or component golang-github-spf13-cobra Operating systems & Components / Operating system package or component golang-github-sourcegraph-syntaxhighlight Operating systems & Components / Operating system package or component golang-github-sophaskins-efs2tar Operating systems & Components / Operating system package or component golang-github-snappy Operating systems & Components / Operating system package or component golang-github-skynetservices-skydns Operating systems & Components / Operating system package or component golang-github-skip2-qrcode Operating systems & Components / Operating system package or component golang-github-shurcool-vfsgen Operating systems & Components / Operating system package or component golang-github-shulhan-bindata Operating systems & Components / Operating system package or component golang-github-shopify-toxiproxy Operating systems & Components / Operating system package or component golang-github-shellcode33-vm-detection Operating systems & Components / Operating system package or component golang-github-segmentio-ksuid Operating systems & Components / Operating system package or component golang-github-rwcarlsen-goexif Operating systems & Components / Operating system package or component golang-github-rubenv-sql-migrate Operating systems & Components / Operating system package or component golang-github-rogpeppe-internal Operating systems & Components / Operating system package or component golang-github-redteampentesting-monsoon Operating systems & Components / Operating system package or component golang-github-rcrowley-metrics Operating systems & Components / Operating system package or component golang-github-rakyll-statik Operating systems & Components / Operating system package or component golang-github-quay-goval-parser Operating systems & Components / Operating system package or component golang-github-quay-claircore Operating systems & Components / Operating system package or component golang-github-prometheus-tsdb Operating systems & Components / Operating system package or component golang-github-prometheus-prom2json Operating systems & Components / Operating system package or component golang-github-prometheus-node-exporter Operating systems & Components / Operating system package or component golang-github-prometheus-alertmanager Operating systems & Components / Operating system package or component golang-github-prometheus Operating systems & Components / Operating system package or component golang-github-projectdiscovery-mapcidr Operating systems & Components / Operating system package or component golang-github-projectdiscovery-chaos-client Operating systems & Components / Operating system package or component golang-github-pressly-goose Operating systems & Components / Operating system package or component golang-github-pquerna-ffjson Operating systems & Components / Operating system package or component golang-github-posener-complete-2 Operating systems & Components / Operating system package or component golang-github-posener-complete Operating systems & Components / Operating system package or component golang-github-pkg-diff Operating systems & Components / Operating system package or component golang-github-pierrre-geohash Operating systems & Components / Operating system package or component golang-github-pierrec-lz4 Operating systems & Components / Operating system package or component golang-github-phayes-freeport Operating systems & Components / Operating system package or component golang-github-pelletier-toml-2 Operating systems & Components / Operating system package or component golang-github-pelletier-toml Operating systems & Components / Operating system package or component golang-github-pdfcpu Operating systems & Components / Operating system package or component golang-github-path-network-mmproxy Operating systems & Components / Operating system package or component golang-github-pact-foundation Operating systems & Components / Operating system package or component golang-github-onsi-ginkgo-2 Operating systems & Components / Operating system package or component golang-github-oneofone-xxhash Operating systems & Components / Operating system package or component golang-github-olekukonko-tablewriter Operating systems & Components / Operating system package or component golang-github-oklog-ulid Operating systems & Components / Operating system package or component golang-github-oklog Operating systems & Components / Operating system package or component golang-github-nxadm-tail Operating systems & Components / Operating system package or component golang-github-niklasfasching-org Operating systems & Components / Operating system package or component golang-github-nicksnyder-i18n-2 Operating systems & Components / Operating system package or component golang-github-nbutton23-zxcvbn Operating systems & Components / Operating system package or component golang-github-nats-io-streaming-server Operating systems & Components / Operating system package or component golang-github-nats-io-nkeys Operating systems & Components / Operating system package or component golang-github-mvo5-uboot Operating systems & Components / Operating system package or component golang-github-multiformats-multihash Operating systems & Components / Operating system package or component golang-github-multiformats-multibase Operating systems & Components / Operating system package or component golang-github-mrunalp-fileutils Operating systems & Components / Operating system package or component golang-github-morikuni-aec Operating systems & Components / Operating system package or component golang-github-mock Operating systems & Components / Operating system package or component golang-github-moby-buildkit Operating systems & Components / Operating system package or component golang-github-mmarkdown-mmark Operating systems & Components / Operating system package or component golang-github-microcosm-cc-bluemonday Operating systems & Components / Operating system package or component golang-github-mholt-archiver Operating systems & Components / Operating system package or component golang-github-mgutz-ansi Operating systems & Components / Operating system package or component golang-github-mdlayher-ethernet Operating systems & Components / Operating system package or component golang-github-mdlayher-dhcp6 Operating systems & Components / Operating system package or component golang-github-mattn-colorable Operating systems & Components / Operating system package or component golang-github-mattermost-xml-roundtrip-validator Operating systems & Components / Operating system package or component golang-github-maruel-panicparse Operating systems & Components / Operating system package or component golang-github-martinhoefling-goxkcdpwgen Operating systems & Components / Operating system package or component golang-github-markbates-pkger Operating systems & Components / Operating system package or component golang-github-mailru-easyjson Operating systems & Components / Operating system package or component golang-github-magefile-mage Operating systems & Components / Operating system package or component golang-github-liamg-tml Operating systems & Components / Operating system package or component golang-github-liamg-scout Operating systems & Components / Operating system package or component golang-github-leveldb Operating systems & Components / Operating system package or component golang-github-leonelquinteros-gotext Operating systems & Components / Operating system package or component golang-github-ledisdb Operating systems & Components / Operating system package or component golang-github-kyokomi-emoji Operating systems & Components / Operating system package or component golang-github-krishicks-yaml-patch Operating systems & Components / Operating system package or component golang-github-kr-text Operating systems & Components / Operating system package or component golang-github-jwt Operating systems & Components / Operating system package or component golang-github-jsonnet-bundler Operating systems & Components / Operating system package or component golang-github-jmespath Operating systems & Components / Operating system package or component golang-github-jamesclonk-vultr Operating systems & Components / Operating system package or component golang-github-j-keck-arping Operating systems & Components / Operating system package or component golang-github-intel-goresctrl Operating systems & Components / Operating system package or component golang-github-instrumenta-kubeval Operating systems & Components / Operating system package or component golang-github-insomniacslk-termhook Operating systems & Components / Operating system package or component golang-github-hpcloud-tail Operating systems & Components / Operating system package or component golang-github-hexdigest-gowrap Operating systems & Components / Operating system package or component golang-github-hashicorp-sockaddr Operating systems & Components / Operating system package or component golang-github-hashicorp-serf Operating systems & Components / Operating system package or component golang-github-hashicorp-memdb Operating systems & Components / Operating system package or component golang-github-hashicorp-hclog Operating systems & Components / Operating system package or component golang-github-hashicorp-consul-migrate Operating systems & Components / Operating system package or component golang-github-haproxytech-dataplaneapi Operating systems & Components / Operating system package or component golang-github-haproxytech-client-native Operating systems & Components / Operating system package or component golang-github-gucumber Operating systems & Components / Operating system package or component golang-github-grpc-ecosystem-gateway-2 Operating systems & Components / Operating system package or component golang-github-gorhill-cronexpr Operating systems & Components / Operating system package or component golang-github-googlecloudplatform-cloudsql-proxy Operating systems & Components / Operating system package or component golang-github-googleapis-gnostic Operating systems & Components / Operating system package or component golang-github-google-wire Operating systems & Components / Operating system package or component golang-github-google-slothfs Operating systems & Components / Operating system package or component golang-github-google-pprof Operating systems & Components / Operating system package or component golang-github-google-martian Operating systems & Components / Operating system package or component golang-github-google-jsonnet Operating systems & Components / Operating system package or component golang-github-golangci-lint-1 Operating systems & Components / Operating system package or component golang-github-gojuno-minimock Operating systems & Components / Operating system package or component golang-github-gohugoio-testmodbuilder Operating systems & Components / Operating system package or component golang-github-gohugoio-localescompressed Operating systems & Components / Operating system package or component golang-github-gogo-protobuf Operating systems & Components / Operating system package or component golang-github-gogo-googleapis Operating systems & Components / Operating system package or component golang-github-gocolly-colly-2 Operating systems & Components / Operating system package or component golang-github-goccy-yaml Operating systems & Components / Operating system package or component golang-github-gobwas-ws Operating systems & Components / Operating system package or component golang-github-gobuffalo-here Operating systems & Components / Operating system package or component golang-github-geertjohan-rice Operating systems & Components / Operating system package or component golang-github-gdamore-tcell-2 Operating systems & Components / Operating system package or component golang-github-gdamore-tcell Operating systems & Components / Operating system package or component golang-github-fvbommel-util Operating systems & Components / Operating system package or component golang-github-francoispqt-gojay Operating systems & Components / Operating system package or component golang-github-fernet Operating systems & Components / Operating system package or component golang-github-facebookincubator-nvdtools Operating systems & Components / Operating system package or component golang-github-facebookincubator-ntp Operating systems & Components / Operating system package or component golang-github-facebookincubator-go2chef Operating systems & Components / Operating system package or component golang-github-facebookincubator-dhcplb Operating systems & Components / Operating system package or component golang-github-facebookincubator-contest Operating systems & Components / Operating system package or component golang-github-evanw-esbuild Operating systems & Components / Operating system package or component golang-github-evanphx-json-patch Operating systems & Components / Operating system package or component golang-github-etcd-io-gofail Operating systems & Components / Operating system package or component golang-github-envoyproxy-protoc-gen-validate Operating systems & Components / Operating system package or component golang-github-emersion-smtp Operating systems & Components / Operating system package or component golang-github-elazarl-bindata-assetfs Operating systems & Components / Operating system package or component golang-github-eknkc-amber Operating systems & Components / Operating system package or component golang-github-dustinkirkland-petname Operating systems & Components / Operating system package or component golang-github-dreamacro-shadowsocks2 Operating systems & Components / Operating system package or component golang-github-docker-distribution Operating systems & Components / Operating system package or component golang-github-dgrijalva-jwt Operating systems & Components / Operating system package or component golang-github-deepmap-oapi-codegen Operating systems & Components / Operating system package or component golang-github-dave-jennifer Operating systems & Components / Operating system package or component golang-github-cucumber-godog Operating systems & Components / Operating system package or component golang-github-crossdock Operating systems & Components / Operating system package or component golang-github-cpuguy83-md2man Operating systems & Components / Operating system package or component golang-github-cpu-goacmedns Operating systems & Components / Operating system package or component golang-github-coredns-corefile-migration Operating systems & Components / Operating system package or component golang-github-containernetworking-cni Operating systems & Components / Operating system package or component golang-github-containerd-stargz-snapshotter Operating systems & Components / Operating system package or component golang-github-containerd-fuse-overlayfs-snapshotter Operating systems & Components / Operating system package or component golang-github-containerd-continuity Operating systems & Components / Operating system package or component golang-github-colinmarc-hdfs-2 Operating systems & Components / Operating system package or component golang-github-cockroachdb-pebble Operating systems & Components / Operating system package or component golang-github-cloudflare-redoctober Operating systems & Components / Operating system package or component golang-github-cloudflare Operating systems & Components / Operating system package or component golang-github-client9-plaintext Operating systems & Components / Operating system package or component golang-github-cilium-ebpf Operating systems & Components / Operating system package or component golang-github-chromedp Operating systems & Components / Operating system package or component golang-github-christrenkamp-goxpath Operating systems & Components / Operating system package or component golang-github-chris-ramon-douceur Operating systems & Components / Operating system package or component golang-github-cheekybits-genny Operating systems & Components / Operating system package or component golang-github-chai2010-gettext Operating systems & Components / Operating system package or component golang-github-cespare-xxhash Operating systems & Components / Operating system package or component golang-github-cactus-statsd-client Operating systems & Components / Operating system package or component golang-github-c-bata-prompt Operating systems & Components / Operating system package or component golang-github-burntsushi-xgb Operating systems & Components / Operating system package or component golang-github-burntsushi-toml-test Operating systems & Components / Operating system package or component golang-github-burntsushi-toml Operating systems & Components / Operating system package or component golang-github-bobesa-domain-util Operating systems & Components / Operating system package or component golang-github-bifurcation-mint Operating systems & Components / Operating system package or component golang-github-axgle-mahonia Operating systems & Components / Operating system package or component golang-github-aws-lambda Operating systems & Components / Operating system package or component golang-github-aryann-difflib Operating systems & Components / Operating system package or component golang-github-appc-spec Operating systems & Components / Operating system package or component golang-github-appc-goaci Operating systems & Components / Operating system package or component golang-github-appc-docker2aci Operating systems & Components / Operating system package or component golang-github-apache-beam-2 Operating systems & Components / Operating system package or component golang-github-andybalholm-cascadia Operating systems & Components / Operating system package or component golang-github-aliyun-ossutil Operating systems & Components / Operating system package or component golang-github-aliyun-cli Operating systems & Components / Operating system package or component golang-github-alecthomas-chroma Operating systems & Components / Operating system package or component golang-github-akavel-rsrc Operating systems & Components / Operating system package or component golang-github-ajstarks-deck Operating systems & Components / Operating system package or component golang-github-a8m-tree Operating systems & Components / Operating system package or component golang-github-a8m-envsubst Operating systems & Components / Operating system package or component golang-gioui Operating systems & Components / Operating system package or component golang-etcd-bbolt Operating systems & Components / Operating system package or component golang-contrib-opencensus-resource Operating systems & Components / Operating system package or component golang-bug-serial-1 Operating systems & Components / Operating system package or component golang-ariga-atlas Operating systems & Components / Operating system package or component gojq Operating systems & Components / Operating system package or component godotenv Operating systems & Components / Operating system package or component godoctor Operating systems & Components / Operating system package or component gobuster Operating systems & Components / Operating system package or component goaltdns Operating systems & Components / Operating system package or component glide Operating systems & Components / Operating system package or component gitjacker Operating systems & Components / Operating system package or component gh Operating systems & Components / Operating system package or component geoipupdate Operating systems & Components / Operating system package or component ffuf Operating systems & Components / Operating system package or component exercism Operating systems & Components / Operating system package or component duf Operating systems & Components / Operating system package or component douceur Operating systems & Components / Operating system package or component dnsx Operating systems & Components / Operating system package or component dnscrypt-proxy Operating systems & Components / Operating system package or component direnv Operating systems & Components / Operating system package or component containerd Operating systems & Components / Operating system package or component commit-stream Operating systems & Components / Operating system package or component clash Operating systems & Components / Operating system package or component chisel Operating systems & Components / Operating system package or component cadvisor Operating systems & Components / Operating system package or component caddy Operating systems & Components / Operating system package or component butane Operating systems & Components / Operating system package or component bettercap Operating systems & Components / Operating system package or component assetfinder Operating systems & Components / Operating system package or component asnip Operating systems & Components / Operating system package or component asciigraph Operating systems & Components / Operating system package or component aron Operating systems & Components / Operating system package or component aquatone Operating systems & Components / Operating system package or component apache-cloudstack-cloudmonkey Operating systems & Components / Operating system package or component age Operating systems & Components / Operating system package or component aerc Operating systems & Components / Operating system package or component act Operating systems & Components / Operating system package or component 3mux Operating systems & Components / Operating system package or component |
Vendor | Fedoraproject |
Security Bulletin
This security bulletin contains information about 5 vulnerabilities.
EUVDB-ID: #VU64266
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-24675
CWE-ID:
CWE-120 - Buffer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the Golang's library encoding/pem. A remote attacker can send to victim a large (more than 5 MB) PEM input to cause a stack overflow in Decode and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsFedora: 35
yubihsm-connector: before 3.0.2-2.fc35
yggdrasil: before 0.2.98^1.ffb580f-0.2.20220127gitffb580f.fc35
xq: before 0.0.7-4.fc35
wgctrl: before 0-0.11.20210811git4253848.fc35
weldr-client: before 35.5-2.fc35
webanalyze: before 0.3.1-6.fc35
vultr-cli: before 2.14.2-2.fc35
vultr: before 1.15.0-9.fc35
vgrep: before 2.5.6-2.fc35
tinygo: before 0.23.0-5.fc35
tiedot: before 3.4-8.fc35
terrier: before 0.0.2-6.fc35
sysutil: before 0-0.7.20200615git15668db.fc35
source-to-image: before 1.3.1-4.fc35
snowcrash: before 0-0.7.20201119git49b99ad.fc35
snapd: before 2.56.2-2.fc35
shhgit: before 0.2-7.fc35
shellz: before 1.5.0-7.fc35
runc: before 1.1.2-2.fc35
reg: before 0.16.1-8.fc35
powerline-go: before 1.22.1-2.fc35
podman-tui: before 0.2.1-2.fc35
ohmybackup: before 0-0.6.20200526git50f2fce.fc35
nex: before 20210330-2.fc35
netscanner: before 0-0.5.20201116git8baab36.fc35
nats-server: before 2.1.9-6.fc35
mqttcli: before 0.2.3-2.fc35
moby-engine: before 20.10.17-4.fc35
micro: before 2.0.8-5.fc35
meshbird: before 2.3-6.fc35
meg: before 0.2.4-6.fc35
mass3: before 0-0.6.20200627gite1d5f1a.fc35
manifest-tool: before 1.0.3-5.fc35
kiln: before 0.3.1-3.fc35
jid: before 0.7.6-9.fc35
ignition: before 2.14.0-3.fc35
hulk: before 0-0.6.20200620git9670699.fc35
httprobe: before 0.1.2-6.fc35
httpdump: before 0-0.6.20200714gite6fa868.fc35
htmltest: before 0.15.0-3.fc35
hcloud: before 1.29.5-2.fc35
hakrevdns: before 0-0.5.20201116git9fa2d59.fc35
grpcurl: before 1.8.6-3.fc35
gotags: before 1.4.1-8.fc35
gopass: before 1.13.1-3.fc35
google-guest-agent: before 20201217.02-4.fc35
goloris: before 0-0.6.20200326gita59fafb.fc35
golang-x-tools: before 0.1.10-2.fc35
golang-x-text: before 0.3.7-3.fc35~bootstrap
golang-x-perf: before 0-0.15.20210123gitbdcc622.fc35
golang-x-mod: before 0.6.0~dev-3.20220330git9b9b3d8.fc35
golang-x-build: before 0-0.21.20201229git0a4bf69.fc35
golang-vbom-util: before 0-0.11.20190520gitefcd4e0.fc35
golang-storj-drpc: before 0.0.31-2.fc35
golang-sourcegraph-appdash: before 0-0.9.20210113gitebfcffb.fc35
golang-mvdan-xurls: before 2.2.0-6.fc35
golang-mvdan-sh-3: before 3.4.3-4.fc35
golang-mongodb-mongo-driver: before 1.4.5-6.fc35
golang-modernc-golex: before 1.0.1-5.fc35
golang-k8s-sample-controller: before 1.22.0-4.fc35
golang-k8s-sample-cli-plugin: before 1.22.0-2.fc35
golang-k8s-sample-apiserver: before 1.22.0-5.fc35
golang-k8s-pod-security-admission: before 1.22.0-3.fc35
golang-k8s-kube-openapi: before 0-0.19.20210813git3c81807.fc35
golang-k8s-kube-aggregator: before 1.22.0-4.fc35
golang-k8s-code-generator: before 1.22.0-4.fc35
golang-k8s-apiextensions-apiserver: before 1.22.0-6.fc35
golang-jaytaylor-html2text: before 0-0.2.20220509gitbc68cce.fc35
golang-honnef-tools: before 2021.1-2.fc35
golang-gopkg-src-d-git-4: before 4.13.1-8.fc35
golang-gopkg-square-jose-2: before 2.6.0-3.fc35
golang-gopkg-neurosnap-sentences-1: before 1.0.6-14.fc35
golang-google-protobuf: before 1.27.1-3.fc35
golang-google-appengine: before 1.6.7-5.fc35
golang-gitlab-commonmark-linkify: before 0-0.9.20200805git64bca66.fc35
golang-github-xordataexchange-crypt: before 0.0.2-12.20190412gitb2862e3.fc35
golang-github-xo-terminfo: before 0-0.6.20210113gitc22d04b.fc35
golang-github-vmware-govmomi: before 0.24.0-5.fc35
golang-github-vincent-petithory-dataurl: before 0-0.7.20200110gitd1553a7.fc35
golang-github-vbatts-tar-split: before 0.11.1-10.fc35
golang-github-valyala-fasthttp: before 1.19.0-4.fc35
golang-github-ulikunitz-xz: before 0.5.10-4.fc35
golang-github-uber-athenadriver: before 1.1.12-5.fc35
golang-github-u-root-iscsinl: before 0.1.0-4.fc35
golang-github-twpayne-waypoint: before 0-0.4.20210130git4f8e6bf.fc35
golang-github-twitchtv-twirp: before 8.1.0-4.fc35
golang-github-tklauser-numcpus: before 0.2.3-7.fc35
golang-github-tinylib-msgp: before 1.1.5-5.fc35
golang-github-theupdateframework-notary: before 0.7.0-6.fc35
golang-github-theoapp-theo-agent: before 0.14.0-4.fc35
golang-github-temoto-robotstxt: before 1.1.1-5.fc35
golang-github-tdewolff-minify: before 2.11.10-3.fc35
golang-github-task: before 3.14.0-2.fc35
golang-github-spyzhov-ajson: before 0.4.2-10.fc35
golang-github-spf13-cobra: before 1.4.0-3.fc35
golang-github-sourcegraph-syntaxhighlight: before 0-0.11.20180418gitbd320f5.fc35
golang-github-sophaskins-efs2tar: before 0-0.4.20210317git4db1b0f.fc35
golang-github-snappy: before 0.0.2-6.fc35
golang-github-skynetservices-skydns: before 2.5.3-22.20200802git94b2ea0.fc35
golang-github-skip2-qrcode: before 0-2.20220316gitda1b656.fc35
golang-github-shurcool-vfsgen: before 0-0.11.20210113git0d455de.fc35
golang-github-shulhan-bindata: before 3.6.1-4.fc35
golang-github-shopify-toxiproxy: before 2.1.4-10.fc35
golang-github-shellcode33-vm-detection: before 0-0.6.20200715git4fd05cb.fc35
golang-github-segmentio-ksuid: before 1.0.4-3.fc35
golang-github-rwcarlsen-goexif: before 0-0.9.20191017git9e8deec.fc35
golang-github-rubenv-sql-migrate: before 0-0.4.20210529gita32ed26.fc35
golang-github-rogpeppe-internal: before 1.8.1-2.fc35
golang-github-redteampentesting-monsoon: before 0.6.0-6.fc35
golang-github-rcrowley-metrics: before 0-0.28.20210110gitcf1acfc.fc35
golang-github-rakyll-statik: before 0.1.7-4.fc35
golang-github-quay-goval-parser: before 0.8.6-4.fc35
golang-github-quay-claircore: before 0.5.4-5.fc35
golang-github-prometheus-tsdb: before 0.10.0-8.fc35
golang-github-prometheus-prom2json: before 1.3.0-8.20210811git90766c0.fc35
golang-github-prometheus-node-exporter: before 1.3.1-9.fc35
golang-github-prometheus-alertmanager: before 0.23.0-10.fc35
golang-github-prometheus: before 2.32.1-6.fc35
golang-github-projectdiscovery-mapcidr: before 0.0.8-3.fc35
golang-github-projectdiscovery-chaos-client: before 0.2.0-2.fc35
golang-github-pressly-goose: before 2.7.0-4.fc35
golang-github-pquerna-ffjson: before 0-0.9.20200730gitaa0246c.fc35
golang-github-posener-complete-2: before 2.0.1~alpha.13-5.fc35
golang-github-posener-complete: before 1.2.3-8.fc35
golang-github-pkg-diff: before 0-0.4.20210406git20ebb0f.fc35
golang-github-pierrre-geohash: before 1.0.0-4.fc35
golang-github-pierrec-lz4: before 4.1.3-5.fc35
golang-github-phayes-freeport: before 1.0.2-6.fc35
golang-github-pelletier-toml-2: before 2.0.0~beta.8-4.fc35
golang-github-pelletier-toml: before 1.9.4-2.fc35
golang-github-pdfcpu: before 0.3.13-2.fc35
golang-github-path-network-mmproxy: before 2.1-3.fc35
golang-github-pact-foundation: before 1.5.1-6.fc35
golang-github-onsi-ginkgo-2: before 2.1.4-2.fc35
golang-github-oneofone-xxhash: before 1.2.8-5.fc35
golang-github-olekukonko-tablewriter: before 0.0.5-3.fc35
golang-github-oklog-ulid: before 2.0.2-10.fc35
golang-github-oklog: before 0.3.2-11.20190701gitca7cdf5.fc35
golang-github-nxadm-tail: before 1.4.6-4.fc35
golang-github-niklasfasching-org: before 1.6.2-2.fc35
golang-github-nicksnyder-i18n-2: before 2.1.2-5.fc35
golang-github-nbutton23-zxcvbn: before 0.1-8.20210110gite56b841.fc35
golang-github-nats-io-streaming-server: before 0.20.0-5.fc35
golang-github-nats-io-nkeys: before 0.2.0-5.fc35
golang-github-mvo5-uboot: before 0.4-10.fc35
golang-github-multiformats-multihash: before 0.1.0-2.fc35
golang-github-multiformats-multibase: before 0.0.3-2.20220213gitf067816.fc35
golang-github-mrunalp-fileutils: before 0.5.0-5.fc35
golang-github-morikuni-aec: before 1.0.0-5.fc35
golang-github-mock: before 1.4.4-4.fc35
golang-github-moby-buildkit: before 0.9.0-4.fc35~bootstrap
golang-github-mmarkdown-mmark: before 2.2.10-5.fc35
golang-github-microcosm-cc-bluemonday: before 1.0.17-3.fc35
golang-github-mholt-archiver: before 3.5.1-3.fc35
golang-github-mgutz-ansi: before 0-0.13.20200729gitd51e80e.fc35
golang-github-mdlayher-ethernet: before 0-0.5.20201109git0394541.fc35
golang-github-mdlayher-dhcp6: before 0-0.8.20200429git2a67805.fc35
golang-github-mattn-colorable: before 0.1.8-7.fc35
golang-github-mattermost-xml-roundtrip-validator: before 0-0.5.20210103git8fd2afa.fc35
golang-github-maruel-panicparse: before 1.6.0-5.fc35
golang-github-martinhoefling-goxkcdpwgen: before 0.1.0-2.fc35
golang-github-markbates-pkger: before 0.17.1-5.fc35
golang-github-mailru-easyjson: before 0.7.6-5.fc35
golang-github-magefile-mage: before 1.11.0-5.fc35
golang-github-liamg-tml: before 0.3.0-4.fc35
golang-github-liamg-scout: before 0.12.0-5.fc35
golang-github-leveldb: before 0-0.9.20190701git259d925.fc35
golang-github-leonelquinteros-gotext: before 1.5.0-2.fc35
golang-github-ledisdb: before 0.6-5.20210112gitd35789e.fc35
golang-github-kyokomi-emoji: before 2.2.8-5.fc35
golang-github-krishicks-yaml-patch: before 0.0.10-8.20200307git05b3177.fc35
golang-github-kr-text: before 0.2.0-5.fc35
golang-github-jwt: before 3.2.2-3.fc35
golang-github-jsonnet-bundler: before 0.4.0-8.fc35
golang-github-jmespath: before 0.4.0-5.fc35
golang-github-jamesclonk-vultr: before 2.0.2-4.fc35
golang-github-j-keck-arping: before 1.0.1-4.fc35
golang-github-intel-goresctrl: before 0.2.0-6.fc35
golang-github-instrumenta-kubeval: before 0.15.0-8.fc35
golang-github-insomniacslk-termhook: before 0-6.20210406gita267c97.fc35
golang-github-hpcloud-tail: before 1.0.0-10.20190325gita1dbeea.fc35
golang-github-hexdigest-gowrap: before 1.1.12-4.fc35
golang-github-hashicorp-sockaddr: before 1.0.2-11.fc35
golang-github-hashicorp-serf: before 0.9.5-5.fc35
golang-github-hashicorp-memdb: before 1.3.0-5.fc35
golang-github-hashicorp-hclog: before 0.15.0-5.fc35
golang-github-hashicorp-consul-migrate: before 0.1.0-9.20190602git678fb10.fc35
golang-github-haproxytech-dataplaneapi: before 2.4.4-4.fc35
golang-github-haproxytech-client-native: before 2.5.3-3.fc35
golang-github-gucumber: before 0-0.23.20190703git7d5c79e.fc35
golang-github-grpc-ecosystem-gateway-2: before 2.7.3-4.fc35
golang-github-gorhill-cronexpr: before 1.0.0-4.fc35
golang-github-googlecloudplatform-cloudsql-proxy: before 1.19.1-6.fc35
golang-github-googleapis-gnostic: before 0.5.3-6.fc35
golang-github-google-wire: before 0.4.0-6.fc35
golang-github-google-slothfs: before 0-0.11.20200727git59c1163.fc35
golang-github-google-pprof: before 0-16.20210802gitc50bf4f.fc35
golang-github-google-martian: before 3.1.0-9.fc35
golang-github-google-jsonnet: before 0.17.0-5.fc35
golang-github-golangci-lint-1: before 0-0.5.20200828gitd2cdd8c.fc35
golang-github-gojuno-minimock: before 3.0.10-3.fc35
golang-github-gohugoio-testmodbuilder: before 0-0.10.20201030git72e1e0c.fc35
golang-github-gohugoio-localescompressed: before 1.0.1-2.fc35
golang-github-gogo-protobuf: before 1.3.2-5.fc35
golang-github-gogo-googleapis: before 1.4.1-4.fc35
golang-github-gocolly-colly-2: before 2.1.0-4.20210920git2f09941.fc35
golang-github-goccy-yaml: before 1.9.5-3.fc35
golang-github-gobwas-ws: before 1.1.0-3.fc35
golang-github-gobuffalo-here: before 0.6.2-5.fc35
golang-github-geertjohan-rice: before 1.0.2-5.fc35
golang-github-gdamore-tcell-2: before 2.5.0-2.fc35
golang-github-gdamore-tcell: before 1.4.0-5.fc35
golang-github-fvbommel-util: before 0.0.3-5.fc35
golang-github-francoispqt-gojay: before 1.2.13-7.fc35
golang-github-fernet: before 0-0.9.20200726giteff2850.fc35
golang-github-facebookincubator-nvdtools: before 0.1.4-5.fc35
golang-github-facebookincubator-ntp: before 0-0.5.20210617git69c3282.fc35
golang-github-facebookincubator-go2chef: before 1.0-2.fc35
golang-github-facebookincubator-dhcplb: before 0-0.4.20210706git2e66b27.fc35
golang-github-facebookincubator-contest: before 0-0.4.20210706gitceebc35.fc35
golang-github-evanw-esbuild: before 0.14.38-2.fc35
golang-github-evanphx-json-patch: before 5.5.0-3.fc35
golang-github-etcd-io-gofail: before 0-0.3.20210808gitad7f989.fc35
golang-github-envoyproxy-protoc-gen-validate: before 0.4.1-6.fc35
golang-github-emersion-smtp: before 0.15.0-4.fc35
golang-github-elazarl-bindata-assetfs: before 1.0.1-9.fc35
golang-github-eknkc-amber: before 0-0.17.20190601gitcdade1c.fc35
golang-github-dustinkirkland-petname: before 0-0.5.20200605git8e5a1ed.fc35
golang-github-dreamacro-shadowsocks2: before 0.1.7-3.fc35
golang-github-docker-distribution: before 2.7.1-9.20200815git35b26de.fc35
golang-github-dgrijalva-jwt: before 3.2.0-11.fc35
golang-github-deepmap-oapi-codegen: before 1.8.2-3.fc35
golang-github-dave-jennifer: before 1.4.1-5.fc35
golang-github-cucumber-godog: before 0.11.0-4.fc35
golang-github-crossdock: before 0-0.8.20190628git049aabb.fc35
golang-github-cpuguy83-md2man: before 2.0.2-2.fc35
golang-github-cpu-goacmedns: before 0.1.1-5.fc35
golang-github-coredns-corefile-migration: before 1.0.11-6.fc35
golang-github-containernetworking-cni: before 1.1.1-4.fc35
golang-github-containerd-stargz-snapshotter: before 0.10.1-3.fc35
golang-github-containerd-fuse-overlayfs-snapshotter: before 1.0.2-7.fc35
golang-github-containerd-continuity: before 0.2.2-3.fc35
golang-github-colinmarc-hdfs-2: before 2.2.0-4.fc35
golang-github-cockroachdb-pebble: before 0-0.6.20210108git48f5530.fc35
golang-github-cloudflare-redoctober: before 0-0.9.20210114git99c99a8.fc35
golang-github-cloudflare: before 0.17.0-3.fc35
golang-github-client9-plaintext: before 0-0.8.20190703git5bf47e7.fc35
golang-github-cilium-ebpf: before 0.8.0-2.fc35
golang-github-chromedp: before 0.6.12-5.fc35
golang-github-christrenkamp-goxpath: before 0-0.6.20200627gitc5096ec.fc35
golang-github-chris-ramon-douceur: before 0.2.0-5.20200910gitf346305.fc35
golang-github-cheekybits-genny: before 1.0.0-9.20200724git3e22f1a.fc35
golang-github-chai2010-gettext: before 1.0.2-6.fc35
golang-github-cespare-xxhash: before 2.1.1-5.fc35
golang-github-cactus-statsd-client: before 5.0.0-5.fc35
golang-github-c-bata-prompt: before 0.2.6-4.fc35
golang-github-burntsushi-xgb: before 0-0.15.20210108git5f9e7b3.fc35
golang-github-burntsushi-toml-test: before 0.2.0-11.20210108git9767d20.fc35
golang-github-burntsushi-toml: before 1.0.0-5.fc35
golang-github-bobesa-domain-util: before 0-0.6.20200504git4033b5f.fc35
golang-github-bifurcation-mint: before 0-0.9.20200724git93c820e.fc35
golang-github-axgle-mahonia: before 0-0.13.20181112git3358181.fc35
golang-github-aws-lambda: before 1.24.0-3.fc35
golang-github-aryann-difflib: before 0-0.5.20200822gite206f87.fc35
golang-github-appc-spec: before 0.8.11-14.fc35
golang-github-appc-goaci: before 0.1.1-12.fc35
golang-github-appc-docker2aci: before 0.17.2-9.fc35
golang-github-apache-beam-2: before 2.33.0~RC1-7.fc35
golang-github-andybalholm-cascadia: before 1.2.0-6.fc35
golang-github-aliyun-ossutil: before 1.7.9-3.fc35
golang-github-aliyun-cli: before 3.0.104-4.s20220118git031f9f2.fc35
golang-github-alecthomas-chroma: before 0.10.0-3.fc35
golang-github-akavel-rsrc: before 0.10.2-4.fc35
golang-github-ajstarks-deck: before 0-0.12.20210114git30c9fc6.fc35
golang-github-a8m-tree: before 0-0.16.20210725gitce3525c.fc35
golang-github-a8m-envsubst: before 1.3.0-2.fc35
golang-gioui: before 0-8.20201225git18d4dbf.fc35
golang-etcd-bbolt: before 1.3.6-4.fc35
golang-contrib-opencensus-resource: before 0.1.2-7.fc35
golang-bug-serial-1: before 1.3.3-2.fc35
golang-ariga-atlas: before 0.3.6-3.fc35
gojq: before 0.12.8-3.fc35
godotenv: before 1.4.0-4.fc35
godoctor: before 0.6-12.fc35
gobuster: before 3.1.0-3.fc35
goaltdns: before 0-0.7.20200627git2b3e8a3.fc35
glide: before 0.13.2-10.fc35
gitjacker: before 0.0.2-6.fc35
gh: before 2.13.0-3.fc35
geoipupdate: before 4.8.0-3.fc35
ffuf: before 1.0.2-6.fc35
exercism: before 3.0.13-8.fc35
duf: before 0.8.1-3.fc35
douceur: before 0.2.0-14.fc35
dnsx: before 1.1.0-3.fc35
dnscrypt-proxy: before 2.1.1-4.fc35
direnv: before 2.32.1-2.fc35
containerd: before 1.6.6-4.fc35
commit-stream: before 0.1.2-7.fc35
clash: before 1.6.5-3.fc35
chisel: before 1.7.7-3.fc35
cadvisor: before 0.44.1-3.fc35
caddy: before 2.3.0-3.fc35
butane: before 0.15.0-2.fc35
bettercap: before 2.32.0-4.fc35
assetfinder: before 0.1.0-6.fc35
asnip: before 0-0.6.20200618git44ba98b.fc35
asciigraph: before 0.5.5-2.fc35
aron: before 0-0.6.20200626git7eade58.fc35
aquatone: before 1.7.0-7.fc35
apache-cloudstack-cloudmonkey: before 6.2.0-3.fc35
age: before 1.0.0-5.fc35
aerc: before 0.10.0-4.fc35
act: before 1.6.0-6.fc35
3mux: before 1.1.0-5.fc35
CPE2.3https://bodhi.fedoraproject.org/updates/FEDORA-2022-3969b64d4b
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU64269
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-28327
CWE-ID:
CWE-190 - Integer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to integer overflow in the Golang's library crypto/elliptic. A remote attacker can send a specially crafted scalar input longer than 32 bytes to cause P256().ScalarMult or P256().ScalarBaseMult to panic and perform a denial of service attack.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsFedora: 35
yubihsm-connector: before 3.0.2-2.fc35
yggdrasil: before 0.2.98^1.ffb580f-0.2.20220127gitffb580f.fc35
xq: before 0.0.7-4.fc35
wgctrl: before 0-0.11.20210811git4253848.fc35
weldr-client: before 35.5-2.fc35
webanalyze: before 0.3.1-6.fc35
vultr-cli: before 2.14.2-2.fc35
vultr: before 1.15.0-9.fc35
vgrep: before 2.5.6-2.fc35
tinygo: before 0.23.0-5.fc35
tiedot: before 3.4-8.fc35
terrier: before 0.0.2-6.fc35
sysutil: before 0-0.7.20200615git15668db.fc35
source-to-image: before 1.3.1-4.fc35
snowcrash: before 0-0.7.20201119git49b99ad.fc35
snapd: before 2.56.2-2.fc35
shhgit: before 0.2-7.fc35
shellz: before 1.5.0-7.fc35
runc: before 1.1.2-2.fc35
reg: before 0.16.1-8.fc35
powerline-go: before 1.22.1-2.fc35
podman-tui: before 0.2.1-2.fc35
ohmybackup: before 0-0.6.20200526git50f2fce.fc35
nex: before 20210330-2.fc35
netscanner: before 0-0.5.20201116git8baab36.fc35
nats-server: before 2.1.9-6.fc35
mqttcli: before 0.2.3-2.fc35
moby-engine: before 20.10.17-4.fc35
micro: before 2.0.8-5.fc35
meshbird: before 2.3-6.fc35
meg: before 0.2.4-6.fc35
mass3: before 0-0.6.20200627gite1d5f1a.fc35
manifest-tool: before 1.0.3-5.fc35
kiln: before 0.3.1-3.fc35
jid: before 0.7.6-9.fc35
ignition: before 2.14.0-3.fc35
hulk: before 0-0.6.20200620git9670699.fc35
httprobe: before 0.1.2-6.fc35
httpdump: before 0-0.6.20200714gite6fa868.fc35
htmltest: before 0.15.0-3.fc35
hcloud: before 1.29.5-2.fc35
hakrevdns: before 0-0.5.20201116git9fa2d59.fc35
grpcurl: before 1.8.6-3.fc35
gotags: before 1.4.1-8.fc35
gopass: before 1.13.1-3.fc35
google-guest-agent: before 20201217.02-4.fc35
goloris: before 0-0.6.20200326gita59fafb.fc35
golang-x-tools: before 0.1.10-2.fc35
golang-x-text: before 0.3.7-3.fc35~bootstrap
golang-x-perf: before 0-0.15.20210123gitbdcc622.fc35
golang-x-mod: before 0.6.0~dev-3.20220330git9b9b3d8.fc35
golang-x-build: before 0-0.21.20201229git0a4bf69.fc35
golang-vbom-util: before 0-0.11.20190520gitefcd4e0.fc35
golang-storj-drpc: before 0.0.31-2.fc35
golang-sourcegraph-appdash: before 0-0.9.20210113gitebfcffb.fc35
golang-mvdan-xurls: before 2.2.0-6.fc35
golang-mvdan-sh-3: before 3.4.3-4.fc35
golang-mongodb-mongo-driver: before 1.4.5-6.fc35
golang-modernc-golex: before 1.0.1-5.fc35
golang-k8s-sample-controller: before 1.22.0-4.fc35
golang-k8s-sample-cli-plugin: before 1.22.0-2.fc35
golang-k8s-sample-apiserver: before 1.22.0-5.fc35
golang-k8s-pod-security-admission: before 1.22.0-3.fc35
golang-k8s-kube-openapi: before 0-0.19.20210813git3c81807.fc35
golang-k8s-kube-aggregator: before 1.22.0-4.fc35
golang-k8s-code-generator: before 1.22.0-4.fc35
golang-k8s-apiextensions-apiserver: before 1.22.0-6.fc35
golang-jaytaylor-html2text: before 0-0.2.20220509gitbc68cce.fc35
golang-honnef-tools: before 2021.1-2.fc35
golang-gopkg-src-d-git-4: before 4.13.1-8.fc35
golang-gopkg-square-jose-2: before 2.6.0-3.fc35
golang-gopkg-neurosnap-sentences-1: before 1.0.6-14.fc35
golang-google-protobuf: before 1.27.1-3.fc35
golang-google-appengine: before 1.6.7-5.fc35
golang-gitlab-commonmark-linkify: before 0-0.9.20200805git64bca66.fc35
golang-github-xordataexchange-crypt: before 0.0.2-12.20190412gitb2862e3.fc35
golang-github-xo-terminfo: before 0-0.6.20210113gitc22d04b.fc35
golang-github-vmware-govmomi: before 0.24.0-5.fc35
golang-github-vincent-petithory-dataurl: before 0-0.7.20200110gitd1553a7.fc35
golang-github-vbatts-tar-split: before 0.11.1-10.fc35
golang-github-valyala-fasthttp: before 1.19.0-4.fc35
golang-github-ulikunitz-xz: before 0.5.10-4.fc35
golang-github-uber-athenadriver: before 1.1.12-5.fc35
golang-github-u-root-iscsinl: before 0.1.0-4.fc35
golang-github-twpayne-waypoint: before 0-0.4.20210130git4f8e6bf.fc35
golang-github-twitchtv-twirp: before 8.1.0-4.fc35
golang-github-tklauser-numcpus: before 0.2.3-7.fc35
golang-github-tinylib-msgp: before 1.1.5-5.fc35
golang-github-theupdateframework-notary: before 0.7.0-6.fc35
golang-github-theoapp-theo-agent: before 0.14.0-4.fc35
golang-github-temoto-robotstxt: before 1.1.1-5.fc35
golang-github-tdewolff-minify: before 2.11.10-3.fc35
golang-github-task: before 3.14.0-2.fc35
golang-github-spyzhov-ajson: before 0.4.2-10.fc35
golang-github-spf13-cobra: before 1.4.0-3.fc35
golang-github-sourcegraph-syntaxhighlight: before 0-0.11.20180418gitbd320f5.fc35
golang-github-sophaskins-efs2tar: before 0-0.4.20210317git4db1b0f.fc35
golang-github-snappy: before 0.0.2-6.fc35
golang-github-skynetservices-skydns: before 2.5.3-22.20200802git94b2ea0.fc35
golang-github-skip2-qrcode: before 0-2.20220316gitda1b656.fc35
golang-github-shurcool-vfsgen: before 0-0.11.20210113git0d455de.fc35
golang-github-shulhan-bindata: before 3.6.1-4.fc35
golang-github-shopify-toxiproxy: before 2.1.4-10.fc35
golang-github-shellcode33-vm-detection: before 0-0.6.20200715git4fd05cb.fc35
golang-github-segmentio-ksuid: before 1.0.4-3.fc35
golang-github-rwcarlsen-goexif: before 0-0.9.20191017git9e8deec.fc35
golang-github-rubenv-sql-migrate: before 0-0.4.20210529gita32ed26.fc35
golang-github-rogpeppe-internal: before 1.8.1-2.fc35
golang-github-redteampentesting-monsoon: before 0.6.0-6.fc35
golang-github-rcrowley-metrics: before 0-0.28.20210110gitcf1acfc.fc35
golang-github-rakyll-statik: before 0.1.7-4.fc35
golang-github-quay-goval-parser: before 0.8.6-4.fc35
golang-github-quay-claircore: before 0.5.4-5.fc35
golang-github-prometheus-tsdb: before 0.10.0-8.fc35
golang-github-prometheus-prom2json: before 1.3.0-8.20210811git90766c0.fc35
golang-github-prometheus-node-exporter: before 1.3.1-9.fc35
golang-github-prometheus-alertmanager: before 0.23.0-10.fc35
golang-github-prometheus: before 2.32.1-6.fc35
golang-github-projectdiscovery-mapcidr: before 0.0.8-3.fc35
golang-github-projectdiscovery-chaos-client: before 0.2.0-2.fc35
golang-github-pressly-goose: before 2.7.0-4.fc35
golang-github-pquerna-ffjson: before 0-0.9.20200730gitaa0246c.fc35
golang-github-posener-complete-2: before 2.0.1~alpha.13-5.fc35
golang-github-posener-complete: before 1.2.3-8.fc35
golang-github-pkg-diff: before 0-0.4.20210406git20ebb0f.fc35
golang-github-pierrre-geohash: before 1.0.0-4.fc35
golang-github-pierrec-lz4: before 4.1.3-5.fc35
golang-github-phayes-freeport: before 1.0.2-6.fc35
golang-github-pelletier-toml-2: before 2.0.0~beta.8-4.fc35
golang-github-pelletier-toml: before 1.9.4-2.fc35
golang-github-pdfcpu: before 0.3.13-2.fc35
golang-github-path-network-mmproxy: before 2.1-3.fc35
golang-github-pact-foundation: before 1.5.1-6.fc35
golang-github-onsi-ginkgo-2: before 2.1.4-2.fc35
golang-github-oneofone-xxhash: before 1.2.8-5.fc35
golang-github-olekukonko-tablewriter: before 0.0.5-3.fc35
golang-github-oklog-ulid: before 2.0.2-10.fc35
golang-github-oklog: before 0.3.2-11.20190701gitca7cdf5.fc35
golang-github-nxadm-tail: before 1.4.6-4.fc35
golang-github-niklasfasching-org: before 1.6.2-2.fc35
golang-github-nicksnyder-i18n-2: before 2.1.2-5.fc35
golang-github-nbutton23-zxcvbn: before 0.1-8.20210110gite56b841.fc35
golang-github-nats-io-streaming-server: before 0.20.0-5.fc35
golang-github-nats-io-nkeys: before 0.2.0-5.fc35
golang-github-mvo5-uboot: before 0.4-10.fc35
golang-github-multiformats-multihash: before 0.1.0-2.fc35
golang-github-multiformats-multibase: before 0.0.3-2.20220213gitf067816.fc35
golang-github-mrunalp-fileutils: before 0.5.0-5.fc35
golang-github-morikuni-aec: before 1.0.0-5.fc35
golang-github-mock: before 1.4.4-4.fc35
golang-github-moby-buildkit: before 0.9.0-4.fc35~bootstrap
golang-github-mmarkdown-mmark: before 2.2.10-5.fc35
golang-github-microcosm-cc-bluemonday: before 1.0.17-3.fc35
golang-github-mholt-archiver: before 3.5.1-3.fc35
golang-github-mgutz-ansi: before 0-0.13.20200729gitd51e80e.fc35
golang-github-mdlayher-ethernet: before 0-0.5.20201109git0394541.fc35
golang-github-mdlayher-dhcp6: before 0-0.8.20200429git2a67805.fc35
golang-github-mattn-colorable: before 0.1.8-7.fc35
golang-github-mattermost-xml-roundtrip-validator: before 0-0.5.20210103git8fd2afa.fc35
golang-github-maruel-panicparse: before 1.6.0-5.fc35
golang-github-martinhoefling-goxkcdpwgen: before 0.1.0-2.fc35
golang-github-markbates-pkger: before 0.17.1-5.fc35
golang-github-mailru-easyjson: before 0.7.6-5.fc35
golang-github-magefile-mage: before 1.11.0-5.fc35
golang-github-liamg-tml: before 0.3.0-4.fc35
golang-github-liamg-scout: before 0.12.0-5.fc35
golang-github-leveldb: before 0-0.9.20190701git259d925.fc35
golang-github-leonelquinteros-gotext: before 1.5.0-2.fc35
golang-github-ledisdb: before 0.6-5.20210112gitd35789e.fc35
golang-github-kyokomi-emoji: before 2.2.8-5.fc35
golang-github-krishicks-yaml-patch: before 0.0.10-8.20200307git05b3177.fc35
golang-github-kr-text: before 0.2.0-5.fc35
golang-github-jwt: before 3.2.2-3.fc35
golang-github-jsonnet-bundler: before 0.4.0-8.fc35
golang-github-jmespath: before 0.4.0-5.fc35
golang-github-jamesclonk-vultr: before 2.0.2-4.fc35
golang-github-j-keck-arping: before 1.0.1-4.fc35
golang-github-intel-goresctrl: before 0.2.0-6.fc35
golang-github-instrumenta-kubeval: before 0.15.0-8.fc35
golang-github-insomniacslk-termhook: before 0-6.20210406gita267c97.fc35
golang-github-hpcloud-tail: before 1.0.0-10.20190325gita1dbeea.fc35
golang-github-hexdigest-gowrap: before 1.1.12-4.fc35
golang-github-hashicorp-sockaddr: before 1.0.2-11.fc35
golang-github-hashicorp-serf: before 0.9.5-5.fc35
golang-github-hashicorp-memdb: before 1.3.0-5.fc35
golang-github-hashicorp-hclog: before 0.15.0-5.fc35
golang-github-hashicorp-consul-migrate: before 0.1.0-9.20190602git678fb10.fc35
golang-github-haproxytech-dataplaneapi: before 2.4.4-4.fc35
golang-github-haproxytech-client-native: before 2.5.3-3.fc35
golang-github-gucumber: before 0-0.23.20190703git7d5c79e.fc35
golang-github-grpc-ecosystem-gateway-2: before 2.7.3-4.fc35
golang-github-gorhill-cronexpr: before 1.0.0-4.fc35
golang-github-googlecloudplatform-cloudsql-proxy: before 1.19.1-6.fc35
golang-github-googleapis-gnostic: before 0.5.3-6.fc35
golang-github-google-wire: before 0.4.0-6.fc35
golang-github-google-slothfs: before 0-0.11.20200727git59c1163.fc35
golang-github-google-pprof: before 0-16.20210802gitc50bf4f.fc35
golang-github-google-martian: before 3.1.0-9.fc35
golang-github-google-jsonnet: before 0.17.0-5.fc35
golang-github-golangci-lint-1: before 0-0.5.20200828gitd2cdd8c.fc35
golang-github-gojuno-minimock: before 3.0.10-3.fc35
golang-github-gohugoio-testmodbuilder: before 0-0.10.20201030git72e1e0c.fc35
golang-github-gohugoio-localescompressed: before 1.0.1-2.fc35
golang-github-gogo-protobuf: before 1.3.2-5.fc35
golang-github-gogo-googleapis: before 1.4.1-4.fc35
golang-github-gocolly-colly-2: before 2.1.0-4.20210920git2f09941.fc35
golang-github-goccy-yaml: before 1.9.5-3.fc35
golang-github-gobwas-ws: before 1.1.0-3.fc35
golang-github-gobuffalo-here: before 0.6.2-5.fc35
golang-github-geertjohan-rice: before 1.0.2-5.fc35
golang-github-gdamore-tcell-2: before 2.5.0-2.fc35
golang-github-gdamore-tcell: before 1.4.0-5.fc35
golang-github-fvbommel-util: before 0.0.3-5.fc35
golang-github-francoispqt-gojay: before 1.2.13-7.fc35
golang-github-fernet: before 0-0.9.20200726giteff2850.fc35
golang-github-facebookincubator-nvdtools: before 0.1.4-5.fc35
golang-github-facebookincubator-ntp: before 0-0.5.20210617git69c3282.fc35
golang-github-facebookincubator-go2chef: before 1.0-2.fc35
golang-github-facebookincubator-dhcplb: before 0-0.4.20210706git2e66b27.fc35
golang-github-facebookincubator-contest: before 0-0.4.20210706gitceebc35.fc35
golang-github-evanw-esbuild: before 0.14.38-2.fc35
golang-github-evanphx-json-patch: before 5.5.0-3.fc35
golang-github-etcd-io-gofail: before 0-0.3.20210808gitad7f989.fc35
golang-github-envoyproxy-protoc-gen-validate: before 0.4.1-6.fc35
golang-github-emersion-smtp: before 0.15.0-4.fc35
golang-github-elazarl-bindata-assetfs: before 1.0.1-9.fc35
golang-github-eknkc-amber: before 0-0.17.20190601gitcdade1c.fc35
golang-github-dustinkirkland-petname: before 0-0.5.20200605git8e5a1ed.fc35
golang-github-dreamacro-shadowsocks2: before 0.1.7-3.fc35
golang-github-docker-distribution: before 2.7.1-9.20200815git35b26de.fc35
golang-github-dgrijalva-jwt: before 3.2.0-11.fc35
golang-github-deepmap-oapi-codegen: before 1.8.2-3.fc35
golang-github-dave-jennifer: before 1.4.1-5.fc35
golang-github-cucumber-godog: before 0.11.0-4.fc35
golang-github-crossdock: before 0-0.8.20190628git049aabb.fc35
golang-github-cpuguy83-md2man: before 2.0.2-2.fc35
golang-github-cpu-goacmedns: before 0.1.1-5.fc35
golang-github-coredns-corefile-migration: before 1.0.11-6.fc35
golang-github-containernetworking-cni: before 1.1.1-4.fc35
golang-github-containerd-stargz-snapshotter: before 0.10.1-3.fc35
golang-github-containerd-fuse-overlayfs-snapshotter: before 1.0.2-7.fc35
golang-github-containerd-continuity: before 0.2.2-3.fc35
golang-github-colinmarc-hdfs-2: before 2.2.0-4.fc35
golang-github-cockroachdb-pebble: before 0-0.6.20210108git48f5530.fc35
golang-github-cloudflare-redoctober: before 0-0.9.20210114git99c99a8.fc35
golang-github-cloudflare: before 0.17.0-3.fc35
golang-github-client9-plaintext: before 0-0.8.20190703git5bf47e7.fc35
golang-github-cilium-ebpf: before 0.8.0-2.fc35
golang-github-chromedp: before 0.6.12-5.fc35
golang-github-christrenkamp-goxpath: before 0-0.6.20200627gitc5096ec.fc35
golang-github-chris-ramon-douceur: before 0.2.0-5.20200910gitf346305.fc35
golang-github-cheekybits-genny: before 1.0.0-9.20200724git3e22f1a.fc35
golang-github-chai2010-gettext: before 1.0.2-6.fc35
golang-github-cespare-xxhash: before 2.1.1-5.fc35
golang-github-cactus-statsd-client: before 5.0.0-5.fc35
golang-github-c-bata-prompt: before 0.2.6-4.fc35
golang-github-burntsushi-xgb: before 0-0.15.20210108git5f9e7b3.fc35
golang-github-burntsushi-toml-test: before 0.2.0-11.20210108git9767d20.fc35
golang-github-burntsushi-toml: before 1.0.0-5.fc35
golang-github-bobesa-domain-util: before 0-0.6.20200504git4033b5f.fc35
golang-github-bifurcation-mint: before 0-0.9.20200724git93c820e.fc35
golang-github-axgle-mahonia: before 0-0.13.20181112git3358181.fc35
golang-github-aws-lambda: before 1.24.0-3.fc35
golang-github-aryann-difflib: before 0-0.5.20200822gite206f87.fc35
golang-github-appc-spec: before 0.8.11-14.fc35
golang-github-appc-goaci: before 0.1.1-12.fc35
golang-github-appc-docker2aci: before 0.17.2-9.fc35
golang-github-apache-beam-2: before 2.33.0~RC1-7.fc35
golang-github-andybalholm-cascadia: before 1.2.0-6.fc35
golang-github-aliyun-ossutil: before 1.7.9-3.fc35
golang-github-aliyun-cli: before 3.0.104-4.s20220118git031f9f2.fc35
golang-github-alecthomas-chroma: before 0.10.0-3.fc35
golang-github-akavel-rsrc: before 0.10.2-4.fc35
golang-github-ajstarks-deck: before 0-0.12.20210114git30c9fc6.fc35
golang-github-a8m-tree: before 0-0.16.20210725gitce3525c.fc35
golang-github-a8m-envsubst: before 1.3.0-2.fc35
golang-gioui: before 0-8.20201225git18d4dbf.fc35
golang-etcd-bbolt: before 1.3.6-4.fc35
golang-contrib-opencensus-resource: before 0.1.2-7.fc35
golang-bug-serial-1: before 1.3.3-2.fc35
golang-ariga-atlas: before 0.3.6-3.fc35
gojq: before 0.12.8-3.fc35
godotenv: before 1.4.0-4.fc35
godoctor: before 0.6-12.fc35
gobuster: before 3.1.0-3.fc35
goaltdns: before 0-0.7.20200627git2b3e8a3.fc35
glide: before 0.13.2-10.fc35
gitjacker: before 0.0.2-6.fc35
gh: before 2.13.0-3.fc35
geoipupdate: before 4.8.0-3.fc35
ffuf: before 1.0.2-6.fc35
exercism: before 3.0.13-8.fc35
duf: before 0.8.1-3.fc35
douceur: before 0.2.0-14.fc35
dnsx: before 1.1.0-3.fc35
dnscrypt-proxy: before 2.1.1-4.fc35
direnv: before 2.32.1-2.fc35
containerd: before 1.6.6-4.fc35
commit-stream: before 0.1.2-7.fc35
clash: before 1.6.5-3.fc35
chisel: before 1.7.7-3.fc35
cadvisor: before 0.44.1-3.fc35
caddy: before 2.3.0-3.fc35
butane: before 0.15.0-2.fc35
bettercap: before 2.32.0-4.fc35
assetfinder: before 0.1.0-6.fc35
asnip: before 0-0.6.20200618git44ba98b.fc35
asciigraph: before 0.5.5-2.fc35
aron: before 0-0.6.20200626git7eade58.fc35
aquatone: before 1.7.0-7.fc35
apache-cloudstack-cloudmonkey: before 6.2.0-3.fc35
age: before 1.0.0-5.fc35
aerc: before 0.10.0-4.fc35
act: before 1.6.0-6.fc35
3mux: before 1.1.0-5.fc35
CPE2.3https://bodhi.fedoraproject.org/updates/FEDORA-2022-3969b64d4b
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU63173
Risk: Low
CVSSv4.0: 1.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-29526
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to the Faccessat function can incorrectly report that a file is accessible, when called with a non-zero flags parameter. An attacker can bypass implemented security restrictions.
Install updates from vendor's repository.
Vulnerable software versionsFedora: 35
yubihsm-connector: before 3.0.2-2.fc35
yggdrasil: before 0.2.98^1.ffb580f-0.2.20220127gitffb580f.fc35
xq: before 0.0.7-4.fc35
wgctrl: before 0-0.11.20210811git4253848.fc35
weldr-client: before 35.5-2.fc35
webanalyze: before 0.3.1-6.fc35
vultr-cli: before 2.14.2-2.fc35
vultr: before 1.15.0-9.fc35
vgrep: before 2.5.6-2.fc35
tinygo: before 0.23.0-5.fc35
tiedot: before 3.4-8.fc35
terrier: before 0.0.2-6.fc35
sysutil: before 0-0.7.20200615git15668db.fc35
source-to-image: before 1.3.1-4.fc35
snowcrash: before 0-0.7.20201119git49b99ad.fc35
snapd: before 2.56.2-2.fc35
shhgit: before 0.2-7.fc35
shellz: before 1.5.0-7.fc35
runc: before 1.1.2-2.fc35
reg: before 0.16.1-8.fc35
powerline-go: before 1.22.1-2.fc35
podman-tui: before 0.2.1-2.fc35
ohmybackup: before 0-0.6.20200526git50f2fce.fc35
nex: before 20210330-2.fc35
netscanner: before 0-0.5.20201116git8baab36.fc35
nats-server: before 2.1.9-6.fc35
mqttcli: before 0.2.3-2.fc35
moby-engine: before 20.10.17-4.fc35
micro: before 2.0.8-5.fc35
meshbird: before 2.3-6.fc35
meg: before 0.2.4-6.fc35
mass3: before 0-0.6.20200627gite1d5f1a.fc35
manifest-tool: before 1.0.3-5.fc35
kiln: before 0.3.1-3.fc35
jid: before 0.7.6-9.fc35
ignition: before 2.14.0-3.fc35
hulk: before 0-0.6.20200620git9670699.fc35
httprobe: before 0.1.2-6.fc35
httpdump: before 0-0.6.20200714gite6fa868.fc35
htmltest: before 0.15.0-3.fc35
hcloud: before 1.29.5-2.fc35
hakrevdns: before 0-0.5.20201116git9fa2d59.fc35
grpcurl: before 1.8.6-3.fc35
gotags: before 1.4.1-8.fc35
gopass: before 1.13.1-3.fc35
google-guest-agent: before 20201217.02-4.fc35
goloris: before 0-0.6.20200326gita59fafb.fc35
golang-x-tools: before 0.1.10-2.fc35
golang-x-text: before 0.3.7-3.fc35~bootstrap
golang-x-perf: before 0-0.15.20210123gitbdcc622.fc35
golang-x-mod: before 0.6.0~dev-3.20220330git9b9b3d8.fc35
golang-x-build: before 0-0.21.20201229git0a4bf69.fc35
golang-vbom-util: before 0-0.11.20190520gitefcd4e0.fc35
golang-storj-drpc: before 0.0.31-2.fc35
golang-sourcegraph-appdash: before 0-0.9.20210113gitebfcffb.fc35
golang-mvdan-xurls: before 2.2.0-6.fc35
golang-mvdan-sh-3: before 3.4.3-4.fc35
golang-mongodb-mongo-driver: before 1.4.5-6.fc35
golang-modernc-golex: before 1.0.1-5.fc35
golang-k8s-sample-controller: before 1.22.0-4.fc35
golang-k8s-sample-cli-plugin: before 1.22.0-2.fc35
golang-k8s-sample-apiserver: before 1.22.0-5.fc35
golang-k8s-pod-security-admission: before 1.22.0-3.fc35
golang-k8s-kube-openapi: before 0-0.19.20210813git3c81807.fc35
golang-k8s-kube-aggregator: before 1.22.0-4.fc35
golang-k8s-code-generator: before 1.22.0-4.fc35
golang-k8s-apiextensions-apiserver: before 1.22.0-6.fc35
golang-jaytaylor-html2text: before 0-0.2.20220509gitbc68cce.fc35
golang-honnef-tools: before 2021.1-2.fc35
golang-gopkg-src-d-git-4: before 4.13.1-8.fc35
golang-gopkg-square-jose-2: before 2.6.0-3.fc35
golang-gopkg-neurosnap-sentences-1: before 1.0.6-14.fc35
golang-google-protobuf: before 1.27.1-3.fc35
golang-google-appengine: before 1.6.7-5.fc35
golang-gitlab-commonmark-linkify: before 0-0.9.20200805git64bca66.fc35
golang-github-xordataexchange-crypt: before 0.0.2-12.20190412gitb2862e3.fc35
golang-github-xo-terminfo: before 0-0.6.20210113gitc22d04b.fc35
golang-github-vmware-govmomi: before 0.24.0-5.fc35
golang-github-vincent-petithory-dataurl: before 0-0.7.20200110gitd1553a7.fc35
golang-github-vbatts-tar-split: before 0.11.1-10.fc35
golang-github-valyala-fasthttp: before 1.19.0-4.fc35
golang-github-ulikunitz-xz: before 0.5.10-4.fc35
golang-github-uber-athenadriver: before 1.1.12-5.fc35
golang-github-u-root-iscsinl: before 0.1.0-4.fc35
golang-github-twpayne-waypoint: before 0-0.4.20210130git4f8e6bf.fc35
golang-github-twitchtv-twirp: before 8.1.0-4.fc35
golang-github-tklauser-numcpus: before 0.2.3-7.fc35
golang-github-tinylib-msgp: before 1.1.5-5.fc35
golang-github-theupdateframework-notary: before 0.7.0-6.fc35
golang-github-theoapp-theo-agent: before 0.14.0-4.fc35
golang-github-temoto-robotstxt: before 1.1.1-5.fc35
golang-github-tdewolff-minify: before 2.11.10-3.fc35
golang-github-task: before 3.14.0-2.fc35
golang-github-spyzhov-ajson: before 0.4.2-10.fc35
golang-github-spf13-cobra: before 1.4.0-3.fc35
golang-github-sourcegraph-syntaxhighlight: before 0-0.11.20180418gitbd320f5.fc35
golang-github-sophaskins-efs2tar: before 0-0.4.20210317git4db1b0f.fc35
golang-github-snappy: before 0.0.2-6.fc35
golang-github-skynetservices-skydns: before 2.5.3-22.20200802git94b2ea0.fc35
golang-github-skip2-qrcode: before 0-2.20220316gitda1b656.fc35
golang-github-shurcool-vfsgen: before 0-0.11.20210113git0d455de.fc35
golang-github-shulhan-bindata: before 3.6.1-4.fc35
golang-github-shopify-toxiproxy: before 2.1.4-10.fc35
golang-github-shellcode33-vm-detection: before 0-0.6.20200715git4fd05cb.fc35
golang-github-segmentio-ksuid: before 1.0.4-3.fc35
golang-github-rwcarlsen-goexif: before 0-0.9.20191017git9e8deec.fc35
golang-github-rubenv-sql-migrate: before 0-0.4.20210529gita32ed26.fc35
golang-github-rogpeppe-internal: before 1.8.1-2.fc35
golang-github-redteampentesting-monsoon: before 0.6.0-6.fc35
golang-github-rcrowley-metrics: before 0-0.28.20210110gitcf1acfc.fc35
golang-github-rakyll-statik: before 0.1.7-4.fc35
golang-github-quay-goval-parser: before 0.8.6-4.fc35
golang-github-quay-claircore: before 0.5.4-5.fc35
golang-github-prometheus-tsdb: before 0.10.0-8.fc35
golang-github-prometheus-prom2json: before 1.3.0-8.20210811git90766c0.fc35
golang-github-prometheus-node-exporter: before 1.3.1-9.fc35
golang-github-prometheus-alertmanager: before 0.23.0-10.fc35
golang-github-prometheus: before 2.32.1-6.fc35
golang-github-projectdiscovery-mapcidr: before 0.0.8-3.fc35
golang-github-projectdiscovery-chaos-client: before 0.2.0-2.fc35
golang-github-pressly-goose: before 2.7.0-4.fc35
golang-github-pquerna-ffjson: before 0-0.9.20200730gitaa0246c.fc35
golang-github-posener-complete-2: before 2.0.1~alpha.13-5.fc35
golang-github-posener-complete: before 1.2.3-8.fc35
golang-github-pkg-diff: before 0-0.4.20210406git20ebb0f.fc35
golang-github-pierrre-geohash: before 1.0.0-4.fc35
golang-github-pierrec-lz4: before 4.1.3-5.fc35
golang-github-phayes-freeport: before 1.0.2-6.fc35
golang-github-pelletier-toml-2: before 2.0.0~beta.8-4.fc35
golang-github-pelletier-toml: before 1.9.4-2.fc35
golang-github-pdfcpu: before 0.3.13-2.fc35
golang-github-path-network-mmproxy: before 2.1-3.fc35
golang-github-pact-foundation: before 1.5.1-6.fc35
golang-github-onsi-ginkgo-2: before 2.1.4-2.fc35
golang-github-oneofone-xxhash: before 1.2.8-5.fc35
golang-github-olekukonko-tablewriter: before 0.0.5-3.fc35
golang-github-oklog-ulid: before 2.0.2-10.fc35
golang-github-oklog: before 0.3.2-11.20190701gitca7cdf5.fc35
golang-github-nxadm-tail: before 1.4.6-4.fc35
golang-github-niklasfasching-org: before 1.6.2-2.fc35
golang-github-nicksnyder-i18n-2: before 2.1.2-5.fc35
golang-github-nbutton23-zxcvbn: before 0.1-8.20210110gite56b841.fc35
golang-github-nats-io-streaming-server: before 0.20.0-5.fc35
golang-github-nats-io-nkeys: before 0.2.0-5.fc35
golang-github-mvo5-uboot: before 0.4-10.fc35
golang-github-multiformats-multihash: before 0.1.0-2.fc35
golang-github-multiformats-multibase: before 0.0.3-2.20220213gitf067816.fc35
golang-github-mrunalp-fileutils: before 0.5.0-5.fc35
golang-github-morikuni-aec: before 1.0.0-5.fc35
golang-github-mock: before 1.4.4-4.fc35
golang-github-moby-buildkit: before 0.9.0-4.fc35~bootstrap
golang-github-mmarkdown-mmark: before 2.2.10-5.fc35
golang-github-microcosm-cc-bluemonday: before 1.0.17-3.fc35
golang-github-mholt-archiver: before 3.5.1-3.fc35
golang-github-mgutz-ansi: before 0-0.13.20200729gitd51e80e.fc35
golang-github-mdlayher-ethernet: before 0-0.5.20201109git0394541.fc35
golang-github-mdlayher-dhcp6: before 0-0.8.20200429git2a67805.fc35
golang-github-mattn-colorable: before 0.1.8-7.fc35
golang-github-mattermost-xml-roundtrip-validator: before 0-0.5.20210103git8fd2afa.fc35
golang-github-maruel-panicparse: before 1.6.0-5.fc35
golang-github-martinhoefling-goxkcdpwgen: before 0.1.0-2.fc35
golang-github-markbates-pkger: before 0.17.1-5.fc35
golang-github-mailru-easyjson: before 0.7.6-5.fc35
golang-github-magefile-mage: before 1.11.0-5.fc35
golang-github-liamg-tml: before 0.3.0-4.fc35
golang-github-liamg-scout: before 0.12.0-5.fc35
golang-github-leveldb: before 0-0.9.20190701git259d925.fc35
golang-github-leonelquinteros-gotext: before 1.5.0-2.fc35
golang-github-ledisdb: before 0.6-5.20210112gitd35789e.fc35
golang-github-kyokomi-emoji: before 2.2.8-5.fc35
golang-github-krishicks-yaml-patch: before 0.0.10-8.20200307git05b3177.fc35
golang-github-kr-text: before 0.2.0-5.fc35
golang-github-jwt: before 3.2.2-3.fc35
golang-github-jsonnet-bundler: before 0.4.0-8.fc35
golang-github-jmespath: before 0.4.0-5.fc35
golang-github-jamesclonk-vultr: before 2.0.2-4.fc35
golang-github-j-keck-arping: before 1.0.1-4.fc35
golang-github-intel-goresctrl: before 0.2.0-6.fc35
golang-github-instrumenta-kubeval: before 0.15.0-8.fc35
golang-github-insomniacslk-termhook: before 0-6.20210406gita267c97.fc35
golang-github-hpcloud-tail: before 1.0.0-10.20190325gita1dbeea.fc35
golang-github-hexdigest-gowrap: before 1.1.12-4.fc35
golang-github-hashicorp-sockaddr: before 1.0.2-11.fc35
golang-github-hashicorp-serf: before 0.9.5-5.fc35
golang-github-hashicorp-memdb: before 1.3.0-5.fc35
golang-github-hashicorp-hclog: before 0.15.0-5.fc35
golang-github-hashicorp-consul-migrate: before 0.1.0-9.20190602git678fb10.fc35
golang-github-haproxytech-dataplaneapi: before 2.4.4-4.fc35
golang-github-haproxytech-client-native: before 2.5.3-3.fc35
golang-github-gucumber: before 0-0.23.20190703git7d5c79e.fc35
golang-github-grpc-ecosystem-gateway-2: before 2.7.3-4.fc35
golang-github-gorhill-cronexpr: before 1.0.0-4.fc35
golang-github-googlecloudplatform-cloudsql-proxy: before 1.19.1-6.fc35
golang-github-googleapis-gnostic: before 0.5.3-6.fc35
golang-github-google-wire: before 0.4.0-6.fc35
golang-github-google-slothfs: before 0-0.11.20200727git59c1163.fc35
golang-github-google-pprof: before 0-16.20210802gitc50bf4f.fc35
golang-github-google-martian: before 3.1.0-9.fc35
golang-github-google-jsonnet: before 0.17.0-5.fc35
golang-github-golangci-lint-1: before 0-0.5.20200828gitd2cdd8c.fc35
golang-github-gojuno-minimock: before 3.0.10-3.fc35
golang-github-gohugoio-testmodbuilder: before 0-0.10.20201030git72e1e0c.fc35
golang-github-gohugoio-localescompressed: before 1.0.1-2.fc35
golang-github-gogo-protobuf: before 1.3.2-5.fc35
golang-github-gogo-googleapis: before 1.4.1-4.fc35
golang-github-gocolly-colly-2: before 2.1.0-4.20210920git2f09941.fc35
golang-github-goccy-yaml: before 1.9.5-3.fc35
golang-github-gobwas-ws: before 1.1.0-3.fc35
golang-github-gobuffalo-here: before 0.6.2-5.fc35
golang-github-geertjohan-rice: before 1.0.2-5.fc35
golang-github-gdamore-tcell-2: before 2.5.0-2.fc35
golang-github-gdamore-tcell: before 1.4.0-5.fc35
golang-github-fvbommel-util: before 0.0.3-5.fc35
golang-github-francoispqt-gojay: before 1.2.13-7.fc35
golang-github-fernet: before 0-0.9.20200726giteff2850.fc35
golang-github-facebookincubator-nvdtools: before 0.1.4-5.fc35
golang-github-facebookincubator-ntp: before 0-0.5.20210617git69c3282.fc35
golang-github-facebookincubator-go2chef: before 1.0-2.fc35
golang-github-facebookincubator-dhcplb: before 0-0.4.20210706git2e66b27.fc35
golang-github-facebookincubator-contest: before 0-0.4.20210706gitceebc35.fc35
golang-github-evanw-esbuild: before 0.14.38-2.fc35
golang-github-evanphx-json-patch: before 5.5.0-3.fc35
golang-github-etcd-io-gofail: before 0-0.3.20210808gitad7f989.fc35
golang-github-envoyproxy-protoc-gen-validate: before 0.4.1-6.fc35
golang-github-emersion-smtp: before 0.15.0-4.fc35
golang-github-elazarl-bindata-assetfs: before 1.0.1-9.fc35
golang-github-eknkc-amber: before 0-0.17.20190601gitcdade1c.fc35
golang-github-dustinkirkland-petname: before 0-0.5.20200605git8e5a1ed.fc35
golang-github-dreamacro-shadowsocks2: before 0.1.7-3.fc35
golang-github-docker-distribution: before 2.7.1-9.20200815git35b26de.fc35
golang-github-dgrijalva-jwt: before 3.2.0-11.fc35
golang-github-deepmap-oapi-codegen: before 1.8.2-3.fc35
golang-github-dave-jennifer: before 1.4.1-5.fc35
golang-github-cucumber-godog: before 0.11.0-4.fc35
golang-github-crossdock: before 0-0.8.20190628git049aabb.fc35
golang-github-cpuguy83-md2man: before 2.0.2-2.fc35
golang-github-cpu-goacmedns: before 0.1.1-5.fc35
golang-github-coredns-corefile-migration: before 1.0.11-6.fc35
golang-github-containernetworking-cni: before 1.1.1-4.fc35
golang-github-containerd-stargz-snapshotter: before 0.10.1-3.fc35
golang-github-containerd-fuse-overlayfs-snapshotter: before 1.0.2-7.fc35
golang-github-containerd-continuity: before 0.2.2-3.fc35
golang-github-colinmarc-hdfs-2: before 2.2.0-4.fc35
golang-github-cockroachdb-pebble: before 0-0.6.20210108git48f5530.fc35
golang-github-cloudflare-redoctober: before 0-0.9.20210114git99c99a8.fc35
golang-github-cloudflare: before 0.17.0-3.fc35
golang-github-client9-plaintext: before 0-0.8.20190703git5bf47e7.fc35
golang-github-cilium-ebpf: before 0.8.0-2.fc35
golang-github-chromedp: before 0.6.12-5.fc35
golang-github-christrenkamp-goxpath: before 0-0.6.20200627gitc5096ec.fc35
golang-github-chris-ramon-douceur: before 0.2.0-5.20200910gitf346305.fc35
golang-github-cheekybits-genny: before 1.0.0-9.20200724git3e22f1a.fc35
golang-github-chai2010-gettext: before 1.0.2-6.fc35
golang-github-cespare-xxhash: before 2.1.1-5.fc35
golang-github-cactus-statsd-client: before 5.0.0-5.fc35
golang-github-c-bata-prompt: before 0.2.6-4.fc35
golang-github-burntsushi-xgb: before 0-0.15.20210108git5f9e7b3.fc35
golang-github-burntsushi-toml-test: before 0.2.0-11.20210108git9767d20.fc35
golang-github-burntsushi-toml: before 1.0.0-5.fc35
golang-github-bobesa-domain-util: before 0-0.6.20200504git4033b5f.fc35
golang-github-bifurcation-mint: before 0-0.9.20200724git93c820e.fc35
golang-github-axgle-mahonia: before 0-0.13.20181112git3358181.fc35
golang-github-aws-lambda: before 1.24.0-3.fc35
golang-github-aryann-difflib: before 0-0.5.20200822gite206f87.fc35
golang-github-appc-spec: before 0.8.11-14.fc35
golang-github-appc-goaci: before 0.1.1-12.fc35
golang-github-appc-docker2aci: before 0.17.2-9.fc35
golang-github-apache-beam-2: before 2.33.0~RC1-7.fc35
golang-github-andybalholm-cascadia: before 1.2.0-6.fc35
golang-github-aliyun-ossutil: before 1.7.9-3.fc35
golang-github-aliyun-cli: before 3.0.104-4.s20220118git031f9f2.fc35
golang-github-alecthomas-chroma: before 0.10.0-3.fc35
golang-github-akavel-rsrc: before 0.10.2-4.fc35
golang-github-ajstarks-deck: before 0-0.12.20210114git30c9fc6.fc35
golang-github-a8m-tree: before 0-0.16.20210725gitce3525c.fc35
golang-github-a8m-envsubst: before 1.3.0-2.fc35
golang-gioui: before 0-8.20201225git18d4dbf.fc35
golang-etcd-bbolt: before 1.3.6-4.fc35
golang-contrib-opencensus-resource: before 0.1.2-7.fc35
golang-bug-serial-1: before 1.3.3-2.fc35
golang-ariga-atlas: before 0.3.6-3.fc35
gojq: before 0.12.8-3.fc35
godotenv: before 1.4.0-4.fc35
godoctor: before 0.6-12.fc35
gobuster: before 3.1.0-3.fc35
goaltdns: before 0-0.7.20200627git2b3e8a3.fc35
glide: before 0.13.2-10.fc35
gitjacker: before 0.0.2-6.fc35
gh: before 2.13.0-3.fc35
geoipupdate: before 4.8.0-3.fc35
ffuf: before 1.0.2-6.fc35
exercism: before 3.0.13-8.fc35
duf: before 0.8.1-3.fc35
douceur: before 0.2.0-14.fc35
dnsx: before 1.1.0-3.fc35
dnscrypt-proxy: before 2.1.1-4.fc35
direnv: before 2.32.1-2.fc35
containerd: before 1.6.6-4.fc35
commit-stream: before 0.1.2-7.fc35
clash: before 1.6.5-3.fc35
chisel: before 1.7.7-3.fc35
cadvisor: before 0.44.1-3.fc35
caddy: before 2.3.0-3.fc35
butane: before 0.15.0-2.fc35
bettercap: before 2.32.0-4.fc35
assetfinder: before 0.1.0-6.fc35
asnip: before 0-0.6.20200618git44ba98b.fc35
asciigraph: before 0.5.5-2.fc35
aron: before 0-0.6.20200626git7eade58.fc35
aquatone: before 1.7.0-7.fc35
apache-cloudstack-cloudmonkey: before 6.2.0-3.fc35
age: before 1.0.0-5.fc35
aerc: before 0.10.0-4.fc35
act: before 1.6.0-6.fc35
3mux: before 1.1.0-5.fc35
CPE2.3https://bodhi.fedoraproject.org/updates/FEDORA-2022-3969b64d4b
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU61599
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-21698
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within method label cardinality. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsFedora: 35
yubihsm-connector: before 3.0.2-2.fc35
yggdrasil: before 0.2.98^1.ffb580f-0.2.20220127gitffb580f.fc35
xq: before 0.0.7-4.fc35
wgctrl: before 0-0.11.20210811git4253848.fc35
weldr-client: before 35.5-2.fc35
webanalyze: before 0.3.1-6.fc35
vultr-cli: before 2.14.2-2.fc35
vultr: before 1.15.0-9.fc35
vgrep: before 2.5.6-2.fc35
tinygo: before 0.23.0-5.fc35
tiedot: before 3.4-8.fc35
terrier: before 0.0.2-6.fc35
sysutil: before 0-0.7.20200615git15668db.fc35
source-to-image: before 1.3.1-4.fc35
snowcrash: before 0-0.7.20201119git49b99ad.fc35
snapd: before 2.56.2-2.fc35
shhgit: before 0.2-7.fc35
shellz: before 1.5.0-7.fc35
runc: before 1.1.2-2.fc35
reg: before 0.16.1-8.fc35
powerline-go: before 1.22.1-2.fc35
podman-tui: before 0.2.1-2.fc35
ohmybackup: before 0-0.6.20200526git50f2fce.fc35
nex: before 20210330-2.fc35
netscanner: before 0-0.5.20201116git8baab36.fc35
nats-server: before 2.1.9-6.fc35
mqttcli: before 0.2.3-2.fc35
moby-engine: before 20.10.17-4.fc35
micro: before 2.0.8-5.fc35
meshbird: before 2.3-6.fc35
meg: before 0.2.4-6.fc35
mass3: before 0-0.6.20200627gite1d5f1a.fc35
manifest-tool: before 1.0.3-5.fc35
kiln: before 0.3.1-3.fc35
jid: before 0.7.6-9.fc35
ignition: before 2.14.0-3.fc35
hulk: before 0-0.6.20200620git9670699.fc35
httprobe: before 0.1.2-6.fc35
httpdump: before 0-0.6.20200714gite6fa868.fc35
htmltest: before 0.15.0-3.fc35
hcloud: before 1.29.5-2.fc35
hakrevdns: before 0-0.5.20201116git9fa2d59.fc35
grpcurl: before 1.8.6-3.fc35
gotags: before 1.4.1-8.fc35
gopass: before 1.13.1-3.fc35
google-guest-agent: before 20201217.02-4.fc35
goloris: before 0-0.6.20200326gita59fafb.fc35
golang-x-tools: before 0.1.10-2.fc35
golang-x-text: before 0.3.7-3.fc35~bootstrap
golang-x-perf: before 0-0.15.20210123gitbdcc622.fc35
golang-x-mod: before 0.6.0~dev-3.20220330git9b9b3d8.fc35
golang-x-build: before 0-0.21.20201229git0a4bf69.fc35
golang-vbom-util: before 0-0.11.20190520gitefcd4e0.fc35
golang-storj-drpc: before 0.0.31-2.fc35
golang-sourcegraph-appdash: before 0-0.9.20210113gitebfcffb.fc35
golang-mvdan-xurls: before 2.2.0-6.fc35
golang-mvdan-sh-3: before 3.4.3-4.fc35
golang-mongodb-mongo-driver: before 1.4.5-6.fc35
golang-modernc-golex: before 1.0.1-5.fc35
golang-k8s-sample-controller: before 1.22.0-4.fc35
golang-k8s-sample-cli-plugin: before 1.22.0-2.fc35
golang-k8s-sample-apiserver: before 1.22.0-5.fc35
golang-k8s-pod-security-admission: before 1.22.0-3.fc35
golang-k8s-kube-openapi: before 0-0.19.20210813git3c81807.fc35
golang-k8s-kube-aggregator: before 1.22.0-4.fc35
golang-k8s-code-generator: before 1.22.0-4.fc35
golang-k8s-apiextensions-apiserver: before 1.22.0-6.fc35
golang-jaytaylor-html2text: before 0-0.2.20220509gitbc68cce.fc35
golang-honnef-tools: before 2021.1-2.fc35
golang-gopkg-src-d-git-4: before 4.13.1-8.fc35
golang-gopkg-square-jose-2: before 2.6.0-3.fc35
golang-gopkg-neurosnap-sentences-1: before 1.0.6-14.fc35
golang-google-protobuf: before 1.27.1-3.fc35
golang-google-appengine: before 1.6.7-5.fc35
golang-gitlab-commonmark-linkify: before 0-0.9.20200805git64bca66.fc35
golang-github-xordataexchange-crypt: before 0.0.2-12.20190412gitb2862e3.fc35
golang-github-xo-terminfo: before 0-0.6.20210113gitc22d04b.fc35
golang-github-vmware-govmomi: before 0.24.0-5.fc35
golang-github-vincent-petithory-dataurl: before 0-0.7.20200110gitd1553a7.fc35
golang-github-vbatts-tar-split: before 0.11.1-10.fc35
golang-github-valyala-fasthttp: before 1.19.0-4.fc35
golang-github-ulikunitz-xz: before 0.5.10-4.fc35
golang-github-uber-athenadriver: before 1.1.12-5.fc35
golang-github-u-root-iscsinl: before 0.1.0-4.fc35
golang-github-twpayne-waypoint: before 0-0.4.20210130git4f8e6bf.fc35
golang-github-twitchtv-twirp: before 8.1.0-4.fc35
golang-github-tklauser-numcpus: before 0.2.3-7.fc35
golang-github-tinylib-msgp: before 1.1.5-5.fc35
golang-github-theupdateframework-notary: before 0.7.0-6.fc35
golang-github-theoapp-theo-agent: before 0.14.0-4.fc35
golang-github-temoto-robotstxt: before 1.1.1-5.fc35
golang-github-tdewolff-minify: before 2.11.10-3.fc35
golang-github-task: before 3.14.0-2.fc35
golang-github-spyzhov-ajson: before 0.4.2-10.fc35
golang-github-spf13-cobra: before 1.4.0-3.fc35
golang-github-sourcegraph-syntaxhighlight: before 0-0.11.20180418gitbd320f5.fc35
golang-github-sophaskins-efs2tar: before 0-0.4.20210317git4db1b0f.fc35
golang-github-snappy: before 0.0.2-6.fc35
golang-github-skynetservices-skydns: before 2.5.3-22.20200802git94b2ea0.fc35
golang-github-skip2-qrcode: before 0-2.20220316gitda1b656.fc35
golang-github-shurcool-vfsgen: before 0-0.11.20210113git0d455de.fc35
golang-github-shulhan-bindata: before 3.6.1-4.fc35
golang-github-shopify-toxiproxy: before 2.1.4-10.fc35
golang-github-shellcode33-vm-detection: before 0-0.6.20200715git4fd05cb.fc35
golang-github-segmentio-ksuid: before 1.0.4-3.fc35
golang-github-rwcarlsen-goexif: before 0-0.9.20191017git9e8deec.fc35
golang-github-rubenv-sql-migrate: before 0-0.4.20210529gita32ed26.fc35
golang-github-rogpeppe-internal: before 1.8.1-2.fc35
golang-github-redteampentesting-monsoon: before 0.6.0-6.fc35
golang-github-rcrowley-metrics: before 0-0.28.20210110gitcf1acfc.fc35
golang-github-rakyll-statik: before 0.1.7-4.fc35
golang-github-quay-goval-parser: before 0.8.6-4.fc35
golang-github-quay-claircore: before 0.5.4-5.fc35
golang-github-prometheus-tsdb: before 0.10.0-8.fc35
golang-github-prometheus-prom2json: before 1.3.0-8.20210811git90766c0.fc35
golang-github-prometheus-node-exporter: before 1.3.1-9.fc35
golang-github-prometheus-alertmanager: before 0.23.0-10.fc35
golang-github-prometheus: before 2.32.1-6.fc35
golang-github-projectdiscovery-mapcidr: before 0.0.8-3.fc35
golang-github-projectdiscovery-chaos-client: before 0.2.0-2.fc35
golang-github-pressly-goose: before 2.7.0-4.fc35
golang-github-pquerna-ffjson: before 0-0.9.20200730gitaa0246c.fc35
golang-github-posener-complete-2: before 2.0.1~alpha.13-5.fc35
golang-github-posener-complete: before 1.2.3-8.fc35
golang-github-pkg-diff: before 0-0.4.20210406git20ebb0f.fc35
golang-github-pierrre-geohash: before 1.0.0-4.fc35
golang-github-pierrec-lz4: before 4.1.3-5.fc35
golang-github-phayes-freeport: before 1.0.2-6.fc35
golang-github-pelletier-toml-2: before 2.0.0~beta.8-4.fc35
golang-github-pelletier-toml: before 1.9.4-2.fc35
golang-github-pdfcpu: before 0.3.13-2.fc35
golang-github-path-network-mmproxy: before 2.1-3.fc35
golang-github-pact-foundation: before 1.5.1-6.fc35
golang-github-onsi-ginkgo-2: before 2.1.4-2.fc35
golang-github-oneofone-xxhash: before 1.2.8-5.fc35
golang-github-olekukonko-tablewriter: before 0.0.5-3.fc35
golang-github-oklog-ulid: before 2.0.2-10.fc35
golang-github-oklog: before 0.3.2-11.20190701gitca7cdf5.fc35
golang-github-nxadm-tail: before 1.4.6-4.fc35
golang-github-niklasfasching-org: before 1.6.2-2.fc35
golang-github-nicksnyder-i18n-2: before 2.1.2-5.fc35
golang-github-nbutton23-zxcvbn: before 0.1-8.20210110gite56b841.fc35
golang-github-nats-io-streaming-server: before 0.20.0-5.fc35
golang-github-nats-io-nkeys: before 0.2.0-5.fc35
golang-github-mvo5-uboot: before 0.4-10.fc35
golang-github-multiformats-multihash: before 0.1.0-2.fc35
golang-github-multiformats-multibase: before 0.0.3-2.20220213gitf067816.fc35
golang-github-mrunalp-fileutils: before 0.5.0-5.fc35
golang-github-morikuni-aec: before 1.0.0-5.fc35
golang-github-mock: before 1.4.4-4.fc35
golang-github-moby-buildkit: before 0.9.0-4.fc35~bootstrap
golang-github-mmarkdown-mmark: before 2.2.10-5.fc35
golang-github-microcosm-cc-bluemonday: before 1.0.17-3.fc35
golang-github-mholt-archiver: before 3.5.1-3.fc35
golang-github-mgutz-ansi: before 0-0.13.20200729gitd51e80e.fc35
golang-github-mdlayher-ethernet: before 0-0.5.20201109git0394541.fc35
golang-github-mdlayher-dhcp6: before 0-0.8.20200429git2a67805.fc35
golang-github-mattn-colorable: before 0.1.8-7.fc35
golang-github-mattermost-xml-roundtrip-validator: before 0-0.5.20210103git8fd2afa.fc35
golang-github-maruel-panicparse: before 1.6.0-5.fc35
golang-github-martinhoefling-goxkcdpwgen: before 0.1.0-2.fc35
golang-github-markbates-pkger: before 0.17.1-5.fc35
golang-github-mailru-easyjson: before 0.7.6-5.fc35
golang-github-magefile-mage: before 1.11.0-5.fc35
golang-github-liamg-tml: before 0.3.0-4.fc35
golang-github-liamg-scout: before 0.12.0-5.fc35
golang-github-leveldb: before 0-0.9.20190701git259d925.fc35
golang-github-leonelquinteros-gotext: before 1.5.0-2.fc35
golang-github-ledisdb: before 0.6-5.20210112gitd35789e.fc35
golang-github-kyokomi-emoji: before 2.2.8-5.fc35
golang-github-krishicks-yaml-patch: before 0.0.10-8.20200307git05b3177.fc35
golang-github-kr-text: before 0.2.0-5.fc35
golang-github-jwt: before 3.2.2-3.fc35
golang-github-jsonnet-bundler: before 0.4.0-8.fc35
golang-github-jmespath: before 0.4.0-5.fc35
golang-github-jamesclonk-vultr: before 2.0.2-4.fc35
golang-github-j-keck-arping: before 1.0.1-4.fc35
golang-github-intel-goresctrl: before 0.2.0-6.fc35
golang-github-instrumenta-kubeval: before 0.15.0-8.fc35
golang-github-insomniacslk-termhook: before 0-6.20210406gita267c97.fc35
golang-github-hpcloud-tail: before 1.0.0-10.20190325gita1dbeea.fc35
golang-github-hexdigest-gowrap: before 1.1.12-4.fc35
golang-github-hashicorp-sockaddr: before 1.0.2-11.fc35
golang-github-hashicorp-serf: before 0.9.5-5.fc35
golang-github-hashicorp-memdb: before 1.3.0-5.fc35
golang-github-hashicorp-hclog: before 0.15.0-5.fc35
golang-github-hashicorp-consul-migrate: before 0.1.0-9.20190602git678fb10.fc35
golang-github-haproxytech-dataplaneapi: before 2.4.4-4.fc35
golang-github-haproxytech-client-native: before 2.5.3-3.fc35
golang-github-gucumber: before 0-0.23.20190703git7d5c79e.fc35
golang-github-grpc-ecosystem-gateway-2: before 2.7.3-4.fc35
golang-github-gorhill-cronexpr: before 1.0.0-4.fc35
golang-github-googlecloudplatform-cloudsql-proxy: before 1.19.1-6.fc35
golang-github-googleapis-gnostic: before 0.5.3-6.fc35
golang-github-google-wire: before 0.4.0-6.fc35
golang-github-google-slothfs: before 0-0.11.20200727git59c1163.fc35
golang-github-google-pprof: before 0-16.20210802gitc50bf4f.fc35
golang-github-google-martian: before 3.1.0-9.fc35
golang-github-google-jsonnet: before 0.17.0-5.fc35
golang-github-golangci-lint-1: before 0-0.5.20200828gitd2cdd8c.fc35
golang-github-gojuno-minimock: before 3.0.10-3.fc35
golang-github-gohugoio-testmodbuilder: before 0-0.10.20201030git72e1e0c.fc35
golang-github-gohugoio-localescompressed: before 1.0.1-2.fc35
golang-github-gogo-protobuf: before 1.3.2-5.fc35
golang-github-gogo-googleapis: before 1.4.1-4.fc35
golang-github-gocolly-colly-2: before 2.1.0-4.20210920git2f09941.fc35
golang-github-goccy-yaml: before 1.9.5-3.fc35
golang-github-gobwas-ws: before 1.1.0-3.fc35
golang-github-gobuffalo-here: before 0.6.2-5.fc35
golang-github-geertjohan-rice: before 1.0.2-5.fc35
golang-github-gdamore-tcell-2: before 2.5.0-2.fc35
golang-github-gdamore-tcell: before 1.4.0-5.fc35
golang-github-fvbommel-util: before 0.0.3-5.fc35
golang-github-francoispqt-gojay: before 1.2.13-7.fc35
golang-github-fernet: before 0-0.9.20200726giteff2850.fc35
golang-github-facebookincubator-nvdtools: before 0.1.4-5.fc35
golang-github-facebookincubator-ntp: before 0-0.5.20210617git69c3282.fc35
golang-github-facebookincubator-go2chef: before 1.0-2.fc35
golang-github-facebookincubator-dhcplb: before 0-0.4.20210706git2e66b27.fc35
golang-github-facebookincubator-contest: before 0-0.4.20210706gitceebc35.fc35
golang-github-evanw-esbuild: before 0.14.38-2.fc35
golang-github-evanphx-json-patch: before 5.5.0-3.fc35
golang-github-etcd-io-gofail: before 0-0.3.20210808gitad7f989.fc35
golang-github-envoyproxy-protoc-gen-validate: before 0.4.1-6.fc35
golang-github-emersion-smtp: before 0.15.0-4.fc35
golang-github-elazarl-bindata-assetfs: before 1.0.1-9.fc35
golang-github-eknkc-amber: before 0-0.17.20190601gitcdade1c.fc35
golang-github-dustinkirkland-petname: before 0-0.5.20200605git8e5a1ed.fc35
golang-github-dreamacro-shadowsocks2: before 0.1.7-3.fc35
golang-github-docker-distribution: before 2.7.1-9.20200815git35b26de.fc35
golang-github-dgrijalva-jwt: before 3.2.0-11.fc35
golang-github-deepmap-oapi-codegen: before 1.8.2-3.fc35
golang-github-dave-jennifer: before 1.4.1-5.fc35
golang-github-cucumber-godog: before 0.11.0-4.fc35
golang-github-crossdock: before 0-0.8.20190628git049aabb.fc35
golang-github-cpuguy83-md2man: before 2.0.2-2.fc35
golang-github-cpu-goacmedns: before 0.1.1-5.fc35
golang-github-coredns-corefile-migration: before 1.0.11-6.fc35
golang-github-containernetworking-cni: before 1.1.1-4.fc35
golang-github-containerd-stargz-snapshotter: before 0.10.1-3.fc35
golang-github-containerd-fuse-overlayfs-snapshotter: before 1.0.2-7.fc35
golang-github-containerd-continuity: before 0.2.2-3.fc35
golang-github-colinmarc-hdfs-2: before 2.2.0-4.fc35
golang-github-cockroachdb-pebble: before 0-0.6.20210108git48f5530.fc35
golang-github-cloudflare-redoctober: before 0-0.9.20210114git99c99a8.fc35
golang-github-cloudflare: before 0.17.0-3.fc35
golang-github-client9-plaintext: before 0-0.8.20190703git5bf47e7.fc35
golang-github-cilium-ebpf: before 0.8.0-2.fc35
golang-github-chromedp: before 0.6.12-5.fc35
golang-github-christrenkamp-goxpath: before 0-0.6.20200627gitc5096ec.fc35
golang-github-chris-ramon-douceur: before 0.2.0-5.20200910gitf346305.fc35
golang-github-cheekybits-genny: before 1.0.0-9.20200724git3e22f1a.fc35
golang-github-chai2010-gettext: before 1.0.2-6.fc35
golang-github-cespare-xxhash: before 2.1.1-5.fc35
golang-github-cactus-statsd-client: before 5.0.0-5.fc35
golang-github-c-bata-prompt: before 0.2.6-4.fc35
golang-github-burntsushi-xgb: before 0-0.15.20210108git5f9e7b3.fc35
golang-github-burntsushi-toml-test: before 0.2.0-11.20210108git9767d20.fc35
golang-github-burntsushi-toml: before 1.0.0-5.fc35
golang-github-bobesa-domain-util: before 0-0.6.20200504git4033b5f.fc35
golang-github-bifurcation-mint: before 0-0.9.20200724git93c820e.fc35
golang-github-axgle-mahonia: before 0-0.13.20181112git3358181.fc35
golang-github-aws-lambda: before 1.24.0-3.fc35
golang-github-aryann-difflib: before 0-0.5.20200822gite206f87.fc35
golang-github-appc-spec: before 0.8.11-14.fc35
golang-github-appc-goaci: before 0.1.1-12.fc35
golang-github-appc-docker2aci: before 0.17.2-9.fc35
golang-github-apache-beam-2: before 2.33.0~RC1-7.fc35
golang-github-andybalholm-cascadia: before 1.2.0-6.fc35
golang-github-aliyun-ossutil: before 1.7.9-3.fc35
golang-github-aliyun-cli: before 3.0.104-4.s20220118git031f9f2.fc35
golang-github-alecthomas-chroma: before 0.10.0-3.fc35
golang-github-akavel-rsrc: before 0.10.2-4.fc35
golang-github-ajstarks-deck: before 0-0.12.20210114git30c9fc6.fc35
golang-github-a8m-tree: before 0-0.16.20210725gitce3525c.fc35
golang-github-a8m-envsubst: before 1.3.0-2.fc35
golang-gioui: before 0-8.20201225git18d4dbf.fc35
golang-etcd-bbolt: before 1.3.6-4.fc35
golang-contrib-opencensus-resource: before 0.1.2-7.fc35
golang-bug-serial-1: before 1.3.3-2.fc35
golang-ariga-atlas: before 0.3.6-3.fc35
gojq: before 0.12.8-3.fc35
godotenv: before 1.4.0-4.fc35
godoctor: before 0.6-12.fc35
gobuster: before 3.1.0-3.fc35
goaltdns: before 0-0.7.20200627git2b3e8a3.fc35
glide: before 0.13.2-10.fc35
gitjacker: before 0.0.2-6.fc35
gh: before 2.13.0-3.fc35
geoipupdate: before 4.8.0-3.fc35
ffuf: before 1.0.2-6.fc35
exercism: before 3.0.13-8.fc35
duf: before 0.8.1-3.fc35
douceur: before 0.2.0-14.fc35
dnsx: before 1.1.0-3.fc35
dnscrypt-proxy: before 2.1.1-4.fc35
direnv: before 2.32.1-2.fc35
containerd: before 1.6.6-4.fc35
commit-stream: before 0.1.2-7.fc35
clash: before 1.6.5-3.fc35
chisel: before 1.7.7-3.fc35
cadvisor: before 0.44.1-3.fc35
caddy: before 2.3.0-3.fc35
butane: before 0.15.0-2.fc35
bettercap: before 2.32.0-4.fc35
assetfinder: before 0.1.0-6.fc35
asnip: before 0-0.6.20200618git44ba98b.fc35
asciigraph: before 0.5.5-2.fc35
aron: before 0-0.6.20200626git7eade58.fc35
aquatone: before 1.7.0-7.fc35
apache-cloudstack-cloudmonkey: before 6.2.0-3.fc35
age: before 1.0.0-5.fc35
aerc: before 0.10.0-4.fc35
act: before 1.6.0-6.fc35
3mux: before 1.1.0-5.fc35
CPE2.3https://bodhi.fedoraproject.org/updates/FEDORA-2022-3969b64d4b
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU66447
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-1996
CWE-ID:
CWE-942 - Overly Permissive Cross-domain Whitelist
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass the CORS protection mechanism.
The vulnerability exists due to incorrect processing of the "Origin" HTTP header that is supplied within HTTP request. A remote attacker can supply arbitrary value via the "Origin" HTTP header, bypass implemented CORS protection mechanism and perform cross-site scripting attacks against the vulnerable application.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsFedora: 35
yubihsm-connector: before 3.0.2-2.fc35
yggdrasil: before 0.2.98^1.ffb580f-0.2.20220127gitffb580f.fc35
xq: before 0.0.7-4.fc35
wgctrl: before 0-0.11.20210811git4253848.fc35
weldr-client: before 35.5-2.fc35
webanalyze: before 0.3.1-6.fc35
vultr-cli: before 2.14.2-2.fc35
vultr: before 1.15.0-9.fc35
vgrep: before 2.5.6-2.fc35
tinygo: before 0.23.0-5.fc35
tiedot: before 3.4-8.fc35
terrier: before 0.0.2-6.fc35
sysutil: before 0-0.7.20200615git15668db.fc35
source-to-image: before 1.3.1-4.fc35
snowcrash: before 0-0.7.20201119git49b99ad.fc35
snapd: before 2.56.2-2.fc35
shhgit: before 0.2-7.fc35
shellz: before 1.5.0-7.fc35
runc: before 1.1.2-2.fc35
reg: before 0.16.1-8.fc35
powerline-go: before 1.22.1-2.fc35
podman-tui: before 0.2.1-2.fc35
ohmybackup: before 0-0.6.20200526git50f2fce.fc35
nex: before 20210330-2.fc35
netscanner: before 0-0.5.20201116git8baab36.fc35
nats-server: before 2.1.9-6.fc35
mqttcli: before 0.2.3-2.fc35
moby-engine: before 20.10.17-4.fc35
micro: before 2.0.8-5.fc35
meshbird: before 2.3-6.fc35
meg: before 0.2.4-6.fc35
mass3: before 0-0.6.20200627gite1d5f1a.fc35
manifest-tool: before 1.0.3-5.fc35
kiln: before 0.3.1-3.fc35
jid: before 0.7.6-9.fc35
ignition: before 2.14.0-3.fc35
hulk: before 0-0.6.20200620git9670699.fc35
httprobe: before 0.1.2-6.fc35
httpdump: before 0-0.6.20200714gite6fa868.fc35
htmltest: before 0.15.0-3.fc35
hcloud: before 1.29.5-2.fc35
hakrevdns: before 0-0.5.20201116git9fa2d59.fc35
grpcurl: before 1.8.6-3.fc35
gotags: before 1.4.1-8.fc35
gopass: before 1.13.1-3.fc35
google-guest-agent: before 20201217.02-4.fc35
goloris: before 0-0.6.20200326gita59fafb.fc35
golang-x-tools: before 0.1.10-2.fc35
golang-x-text: before 0.3.7-3.fc35~bootstrap
golang-x-perf: before 0-0.15.20210123gitbdcc622.fc35
golang-x-mod: before 0.6.0~dev-3.20220330git9b9b3d8.fc35
golang-x-build: before 0-0.21.20201229git0a4bf69.fc35
golang-vbom-util: before 0-0.11.20190520gitefcd4e0.fc35
golang-storj-drpc: before 0.0.31-2.fc35
golang-sourcegraph-appdash: before 0-0.9.20210113gitebfcffb.fc35
golang-mvdan-xurls: before 2.2.0-6.fc35
golang-mvdan-sh-3: before 3.4.3-4.fc35
golang-mongodb-mongo-driver: before 1.4.5-6.fc35
golang-modernc-golex: before 1.0.1-5.fc35
golang-k8s-sample-controller: before 1.22.0-4.fc35
golang-k8s-sample-cli-plugin: before 1.22.0-2.fc35
golang-k8s-sample-apiserver: before 1.22.0-5.fc35
golang-k8s-pod-security-admission: before 1.22.0-3.fc35
golang-k8s-kube-openapi: before 0-0.19.20210813git3c81807.fc35
golang-k8s-kube-aggregator: before 1.22.0-4.fc35
golang-k8s-code-generator: before 1.22.0-4.fc35
golang-k8s-apiextensions-apiserver: before 1.22.0-6.fc35
golang-jaytaylor-html2text: before 0-0.2.20220509gitbc68cce.fc35
golang-honnef-tools: before 2021.1-2.fc35
golang-gopkg-src-d-git-4: before 4.13.1-8.fc35
golang-gopkg-square-jose-2: before 2.6.0-3.fc35
golang-gopkg-neurosnap-sentences-1: before 1.0.6-14.fc35
golang-google-protobuf: before 1.27.1-3.fc35
golang-google-appengine: before 1.6.7-5.fc35
golang-gitlab-commonmark-linkify: before 0-0.9.20200805git64bca66.fc35
golang-github-xordataexchange-crypt: before 0.0.2-12.20190412gitb2862e3.fc35
golang-github-xo-terminfo: before 0-0.6.20210113gitc22d04b.fc35
golang-github-vmware-govmomi: before 0.24.0-5.fc35
golang-github-vincent-petithory-dataurl: before 0-0.7.20200110gitd1553a7.fc35
golang-github-vbatts-tar-split: before 0.11.1-10.fc35
golang-github-valyala-fasthttp: before 1.19.0-4.fc35
golang-github-ulikunitz-xz: before 0.5.10-4.fc35
golang-github-uber-athenadriver: before 1.1.12-5.fc35
golang-github-u-root-iscsinl: before 0.1.0-4.fc35
golang-github-twpayne-waypoint: before 0-0.4.20210130git4f8e6bf.fc35
golang-github-twitchtv-twirp: before 8.1.0-4.fc35
golang-github-tklauser-numcpus: before 0.2.3-7.fc35
golang-github-tinylib-msgp: before 1.1.5-5.fc35
golang-github-theupdateframework-notary: before 0.7.0-6.fc35
golang-github-theoapp-theo-agent: before 0.14.0-4.fc35
golang-github-temoto-robotstxt: before 1.1.1-5.fc35
golang-github-tdewolff-minify: before 2.11.10-3.fc35
golang-github-task: before 3.14.0-2.fc35
golang-github-spyzhov-ajson: before 0.4.2-10.fc35
golang-github-spf13-cobra: before 1.4.0-3.fc35
golang-github-sourcegraph-syntaxhighlight: before 0-0.11.20180418gitbd320f5.fc35
golang-github-sophaskins-efs2tar: before 0-0.4.20210317git4db1b0f.fc35
golang-github-snappy: before 0.0.2-6.fc35
golang-github-skynetservices-skydns: before 2.5.3-22.20200802git94b2ea0.fc35
golang-github-skip2-qrcode: before 0-2.20220316gitda1b656.fc35
golang-github-shurcool-vfsgen: before 0-0.11.20210113git0d455de.fc35
golang-github-shulhan-bindata: before 3.6.1-4.fc35
golang-github-shopify-toxiproxy: before 2.1.4-10.fc35
golang-github-shellcode33-vm-detection: before 0-0.6.20200715git4fd05cb.fc35
golang-github-segmentio-ksuid: before 1.0.4-3.fc35
golang-github-rwcarlsen-goexif: before 0-0.9.20191017git9e8deec.fc35
golang-github-rubenv-sql-migrate: before 0-0.4.20210529gita32ed26.fc35
golang-github-rogpeppe-internal: before 1.8.1-2.fc35
golang-github-redteampentesting-monsoon: before 0.6.0-6.fc35
golang-github-rcrowley-metrics: before 0-0.28.20210110gitcf1acfc.fc35
golang-github-rakyll-statik: before 0.1.7-4.fc35
golang-github-quay-goval-parser: before 0.8.6-4.fc35
golang-github-quay-claircore: before 0.5.4-5.fc35
golang-github-prometheus-tsdb: before 0.10.0-8.fc35
golang-github-prometheus-prom2json: before 1.3.0-8.20210811git90766c0.fc35
golang-github-prometheus-node-exporter: before 1.3.1-9.fc35
golang-github-prometheus-alertmanager: before 0.23.0-10.fc35
golang-github-prometheus: before 2.32.1-6.fc35
golang-github-projectdiscovery-mapcidr: before 0.0.8-3.fc35
golang-github-projectdiscovery-chaos-client: before 0.2.0-2.fc35
golang-github-pressly-goose: before 2.7.0-4.fc35
golang-github-pquerna-ffjson: before 0-0.9.20200730gitaa0246c.fc35
golang-github-posener-complete-2: before 2.0.1~alpha.13-5.fc35
golang-github-posener-complete: before 1.2.3-8.fc35
golang-github-pkg-diff: before 0-0.4.20210406git20ebb0f.fc35
golang-github-pierrre-geohash: before 1.0.0-4.fc35
golang-github-pierrec-lz4: before 4.1.3-5.fc35
golang-github-phayes-freeport: before 1.0.2-6.fc35
golang-github-pelletier-toml-2: before 2.0.0~beta.8-4.fc35
golang-github-pelletier-toml: before 1.9.4-2.fc35
golang-github-pdfcpu: before 0.3.13-2.fc35
golang-github-path-network-mmproxy: before 2.1-3.fc35
golang-github-pact-foundation: before 1.5.1-6.fc35
golang-github-onsi-ginkgo-2: before 2.1.4-2.fc35
golang-github-oneofone-xxhash: before 1.2.8-5.fc35
golang-github-olekukonko-tablewriter: before 0.0.5-3.fc35
golang-github-oklog-ulid: before 2.0.2-10.fc35
golang-github-oklog: before 0.3.2-11.20190701gitca7cdf5.fc35
golang-github-nxadm-tail: before 1.4.6-4.fc35
golang-github-niklasfasching-org: before 1.6.2-2.fc35
golang-github-nicksnyder-i18n-2: before 2.1.2-5.fc35
golang-github-nbutton23-zxcvbn: before 0.1-8.20210110gite56b841.fc35
golang-github-nats-io-streaming-server: before 0.20.0-5.fc35
golang-github-nats-io-nkeys: before 0.2.0-5.fc35
golang-github-mvo5-uboot: before 0.4-10.fc35
golang-github-multiformats-multihash: before 0.1.0-2.fc35
golang-github-multiformats-multibase: before 0.0.3-2.20220213gitf067816.fc35
golang-github-mrunalp-fileutils: before 0.5.0-5.fc35
golang-github-morikuni-aec: before 1.0.0-5.fc35
golang-github-mock: before 1.4.4-4.fc35
golang-github-moby-buildkit: before 0.9.0-4.fc35~bootstrap
golang-github-mmarkdown-mmark: before 2.2.10-5.fc35
golang-github-microcosm-cc-bluemonday: before 1.0.17-3.fc35
golang-github-mholt-archiver: before 3.5.1-3.fc35
golang-github-mgutz-ansi: before 0-0.13.20200729gitd51e80e.fc35
golang-github-mdlayher-ethernet: before 0-0.5.20201109git0394541.fc35
golang-github-mdlayher-dhcp6: before 0-0.8.20200429git2a67805.fc35
golang-github-mattn-colorable: before 0.1.8-7.fc35
golang-github-mattermost-xml-roundtrip-validator: before 0-0.5.20210103git8fd2afa.fc35
golang-github-maruel-panicparse: before 1.6.0-5.fc35
golang-github-martinhoefling-goxkcdpwgen: before 0.1.0-2.fc35
golang-github-markbates-pkger: before 0.17.1-5.fc35
golang-github-mailru-easyjson: before 0.7.6-5.fc35
golang-github-magefile-mage: before 1.11.0-5.fc35
golang-github-liamg-tml: before 0.3.0-4.fc35
golang-github-liamg-scout: before 0.12.0-5.fc35
golang-github-leveldb: before 0-0.9.20190701git259d925.fc35
golang-github-leonelquinteros-gotext: before 1.5.0-2.fc35
golang-github-ledisdb: before 0.6-5.20210112gitd35789e.fc35
golang-github-kyokomi-emoji: before 2.2.8-5.fc35
golang-github-krishicks-yaml-patch: before 0.0.10-8.20200307git05b3177.fc35
golang-github-kr-text: before 0.2.0-5.fc35
golang-github-jwt: before 3.2.2-3.fc35
golang-github-jsonnet-bundler: before 0.4.0-8.fc35
golang-github-jmespath: before 0.4.0-5.fc35
golang-github-jamesclonk-vultr: before 2.0.2-4.fc35
golang-github-j-keck-arping: before 1.0.1-4.fc35
golang-github-intel-goresctrl: before 0.2.0-6.fc35
golang-github-instrumenta-kubeval: before 0.15.0-8.fc35
golang-github-insomniacslk-termhook: before 0-6.20210406gita267c97.fc35
golang-github-hpcloud-tail: before 1.0.0-10.20190325gita1dbeea.fc35
golang-github-hexdigest-gowrap: before 1.1.12-4.fc35
golang-github-hashicorp-sockaddr: before 1.0.2-11.fc35
golang-github-hashicorp-serf: before 0.9.5-5.fc35
golang-github-hashicorp-memdb: before 1.3.0-5.fc35
golang-github-hashicorp-hclog: before 0.15.0-5.fc35
golang-github-hashicorp-consul-migrate: before 0.1.0-9.20190602git678fb10.fc35
golang-github-haproxytech-dataplaneapi: before 2.4.4-4.fc35
golang-github-haproxytech-client-native: before 2.5.3-3.fc35
golang-github-gucumber: before 0-0.23.20190703git7d5c79e.fc35
golang-github-grpc-ecosystem-gateway-2: before 2.7.3-4.fc35
golang-github-gorhill-cronexpr: before 1.0.0-4.fc35
golang-github-googlecloudplatform-cloudsql-proxy: before 1.19.1-6.fc35
golang-github-googleapis-gnostic: before 0.5.3-6.fc35
golang-github-google-wire: before 0.4.0-6.fc35
golang-github-google-slothfs: before 0-0.11.20200727git59c1163.fc35
golang-github-google-pprof: before 0-16.20210802gitc50bf4f.fc35
golang-github-google-martian: before 3.1.0-9.fc35
golang-github-google-jsonnet: before 0.17.0-5.fc35
golang-github-golangci-lint-1: before 0-0.5.20200828gitd2cdd8c.fc35
golang-github-gojuno-minimock: before 3.0.10-3.fc35
golang-github-gohugoio-testmodbuilder: before 0-0.10.20201030git72e1e0c.fc35
golang-github-gohugoio-localescompressed: before 1.0.1-2.fc35
golang-github-gogo-protobuf: before 1.3.2-5.fc35
golang-github-gogo-googleapis: before 1.4.1-4.fc35
golang-github-gocolly-colly-2: before 2.1.0-4.20210920git2f09941.fc35
golang-github-goccy-yaml: before 1.9.5-3.fc35
golang-github-gobwas-ws: before 1.1.0-3.fc35
golang-github-gobuffalo-here: before 0.6.2-5.fc35
golang-github-geertjohan-rice: before 1.0.2-5.fc35
golang-github-gdamore-tcell-2: before 2.5.0-2.fc35
golang-github-gdamore-tcell: before 1.4.0-5.fc35
golang-github-fvbommel-util: before 0.0.3-5.fc35
golang-github-francoispqt-gojay: before 1.2.13-7.fc35
golang-github-fernet: before 0-0.9.20200726giteff2850.fc35
golang-github-facebookincubator-nvdtools: before 0.1.4-5.fc35
golang-github-facebookincubator-ntp: before 0-0.5.20210617git69c3282.fc35
golang-github-facebookincubator-go2chef: before 1.0-2.fc35
golang-github-facebookincubator-dhcplb: before 0-0.4.20210706git2e66b27.fc35
golang-github-facebookincubator-contest: before 0-0.4.20210706gitceebc35.fc35
golang-github-evanw-esbuild: before 0.14.38-2.fc35
golang-github-evanphx-json-patch: before 5.5.0-3.fc35
golang-github-etcd-io-gofail: before 0-0.3.20210808gitad7f989.fc35
golang-github-envoyproxy-protoc-gen-validate: before 0.4.1-6.fc35
golang-github-emersion-smtp: before 0.15.0-4.fc35
golang-github-elazarl-bindata-assetfs: before 1.0.1-9.fc35
golang-github-eknkc-amber: before 0-0.17.20190601gitcdade1c.fc35
golang-github-dustinkirkland-petname: before 0-0.5.20200605git8e5a1ed.fc35
golang-github-dreamacro-shadowsocks2: before 0.1.7-3.fc35
golang-github-docker-distribution: before 2.7.1-9.20200815git35b26de.fc35
golang-github-dgrijalva-jwt: before 3.2.0-11.fc35
golang-github-deepmap-oapi-codegen: before 1.8.2-3.fc35
golang-github-dave-jennifer: before 1.4.1-5.fc35
golang-github-cucumber-godog: before 0.11.0-4.fc35
golang-github-crossdock: before 0-0.8.20190628git049aabb.fc35
golang-github-cpuguy83-md2man: before 2.0.2-2.fc35
golang-github-cpu-goacmedns: before 0.1.1-5.fc35
golang-github-coredns-corefile-migration: before 1.0.11-6.fc35
golang-github-containernetworking-cni: before 1.1.1-4.fc35
golang-github-containerd-stargz-snapshotter: before 0.10.1-3.fc35
golang-github-containerd-fuse-overlayfs-snapshotter: before 1.0.2-7.fc35
golang-github-containerd-continuity: before 0.2.2-3.fc35
golang-github-colinmarc-hdfs-2: before 2.2.0-4.fc35
golang-github-cockroachdb-pebble: before 0-0.6.20210108git48f5530.fc35
golang-github-cloudflare-redoctober: before 0-0.9.20210114git99c99a8.fc35
golang-github-cloudflare: before 0.17.0-3.fc35
golang-github-client9-plaintext: before 0-0.8.20190703git5bf47e7.fc35
golang-github-cilium-ebpf: before 0.8.0-2.fc35
golang-github-chromedp: before 0.6.12-5.fc35
golang-github-christrenkamp-goxpath: before 0-0.6.20200627gitc5096ec.fc35
golang-github-chris-ramon-douceur: before 0.2.0-5.20200910gitf346305.fc35
golang-github-cheekybits-genny: before 1.0.0-9.20200724git3e22f1a.fc35
golang-github-chai2010-gettext: before 1.0.2-6.fc35
golang-github-cespare-xxhash: before 2.1.1-5.fc35
golang-github-cactus-statsd-client: before 5.0.0-5.fc35
golang-github-c-bata-prompt: before 0.2.6-4.fc35
golang-github-burntsushi-xgb: before 0-0.15.20210108git5f9e7b3.fc35
golang-github-burntsushi-toml-test: before 0.2.0-11.20210108git9767d20.fc35
golang-github-burntsushi-toml: before 1.0.0-5.fc35
golang-github-bobesa-domain-util: before 0-0.6.20200504git4033b5f.fc35
golang-github-bifurcation-mint: before 0-0.9.20200724git93c820e.fc35
golang-github-axgle-mahonia: before 0-0.13.20181112git3358181.fc35
golang-github-aws-lambda: before 1.24.0-3.fc35
golang-github-aryann-difflib: before 0-0.5.20200822gite206f87.fc35
golang-github-appc-spec: before 0.8.11-14.fc35
golang-github-appc-goaci: before 0.1.1-12.fc35
golang-github-appc-docker2aci: before 0.17.2-9.fc35
golang-github-apache-beam-2: before 2.33.0~RC1-7.fc35
golang-github-andybalholm-cascadia: before 1.2.0-6.fc35
golang-github-aliyun-ossutil: before 1.7.9-3.fc35
golang-github-aliyun-cli: before 3.0.104-4.s20220118git031f9f2.fc35
golang-github-alecthomas-chroma: before 0.10.0-3.fc35
golang-github-akavel-rsrc: before 0.10.2-4.fc35
golang-github-ajstarks-deck: before 0-0.12.20210114git30c9fc6.fc35
golang-github-a8m-tree: before 0-0.16.20210725gitce3525c.fc35
golang-github-a8m-envsubst: before 1.3.0-2.fc35
golang-gioui: before 0-8.20201225git18d4dbf.fc35
golang-etcd-bbolt: before 1.3.6-4.fc35
golang-contrib-opencensus-resource: before 0.1.2-7.fc35
golang-bug-serial-1: before 1.3.3-2.fc35
golang-ariga-atlas: before 0.3.6-3.fc35
gojq: before 0.12.8-3.fc35
godotenv: before 1.4.0-4.fc35
godoctor: before 0.6-12.fc35
gobuster: before 3.1.0-3.fc35
goaltdns: before 0-0.7.20200627git2b3e8a3.fc35
glide: before 0.13.2-10.fc35
gitjacker: before 0.0.2-6.fc35
gh: before 2.13.0-3.fc35
geoipupdate: before 4.8.0-3.fc35
ffuf: before 1.0.2-6.fc35
exercism: before 3.0.13-8.fc35
duf: before 0.8.1-3.fc35
douceur: before 0.2.0-14.fc35
dnsx: before 1.1.0-3.fc35
dnscrypt-proxy: before 2.1.1-4.fc35
direnv: before 2.32.1-2.fc35
containerd: before 1.6.6-4.fc35
commit-stream: before 0.1.2-7.fc35
clash: before 1.6.5-3.fc35
chisel: before 1.7.7-3.fc35
cadvisor: before 0.44.1-3.fc35
caddy: before 2.3.0-3.fc35
butane: before 0.15.0-2.fc35
bettercap: before 2.32.0-4.fc35
assetfinder: before 0.1.0-6.fc35
asnip: before 0-0.6.20200618git44ba98b.fc35
asciigraph: before 0.5.5-2.fc35
aron: before 0-0.6.20200626git7eade58.fc35
aquatone: before 1.7.0-7.fc35
apache-cloudstack-cloudmonkey: before 6.2.0-3.fc35
age: before 1.0.0-5.fc35
aerc: before 0.10.0-4.fc35
act: before 1.6.0-6.fc35
3mux: before 1.1.0-5.fc35
CPE2.3https://bodhi.fedoraproject.org/updates/FEDORA-2022-3969b64d4b
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.