Lucene search

K
cveLINECVE-2022-41568
HistoryNov 29, 2022 - 5:15 a.m.

CVE-2022-41568

2022-11-2905:15:11
CWE-400
LINE
web.nvd.nist.gov
42
2
cve-2022-41568
line
ios
e2ee
crash

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

38.5%

LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.

Affected configurations

Nvd
Node
linecorplineRange<12.17.0iphone_os
VendorProductVersionCPE
linecorpline*cpe:2.3:a:linecorp:line:*:*:*:*:*:iphone_os:*:*

CNA Affected

[
  {
    "vendor": "LINE Corporation",
    "product": "LINE client for iOS",
    "versions": [
      {
        "version": "<",
        "status": "affected"
      }
    ]
  }
]

Social References

More

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

38.5%

Related for CVE-2022-41568