Lucene search

K
cveRedhatCVE-2022-1249
HistoryApr 29, 2022 - 4:15 p.m.

CVE-2022-1249

2022-04-2916:15:08
CWE-476
redhat
web.nvd.nist.gov
152
4
cve-2022-1249
pesign
null pointer dereference
crash
daemonize

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

AI Score

3.9

Confidence

High

EPSS

0

Percentile

12.6%

A NULL pointer dereference flaw was found in pesign’s cms_set_pw_data() function of the cms_common.c file. The function fails to handle the NULL pwdata invocation from daemon.c, which leads to an explicit NULL dereference and crash on all attempts to daemonize pesign.

Affected configurations

Nvd
Vulners
Node
pesign_projectpesignRange<115
VendorProductVersionCPE
pesign_projectpesign*cpe:2.3:a:pesign_project:pesign:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "pesign",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "pesign 115"
      }
    ]
  }
]

Social References

More

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

AI Score

3.9

Confidence

High

EPSS

0

Percentile

12.6%