Lucene search

K
cveFacebookCVE-2022-38216
HistoryAug 16, 2022 - 1:15 a.m.

CVE-2022-38216

2022-08-1601:15:14
CWE-190
facebook
web.nvd.nist.gov
49
9
cve-2022-38216
mapbox
gl-native library
integer overflow
out of bounds writes
nvd
security vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

38.4%

An integer overflow exists in Mapbox’s closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes, potentially crashing the Mapbox process.

Affected configurations

Nvd
Node
mapboxmaps_software_development_kitRange<10.6.1android
VendorProductVersionCPE
mapboxmaps_software_development_kit*cpe:2.3:a:mapbox:maps_software_development_kit:*:*:*:*:*:android:*:*

CNA Affected

[
  {
    "product": "Mapbox",
    "vendor": "Mapbox",
    "versions": [
      {
        "lessThan": "10.6.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

38.4%

Related for CVE-2022-38216