Lucene search

K
cvelistFacebookCVELIST:CVE-2022-38216
HistoryAug 16, 2022 - 12:34 a.m.

CVE-2022-38216

2022-08-1600:34:54
CWE-190
facebook
www.cve.org
1
mapbox
gl-native
integer overflow
image
out of bounds writes
crash

EPSS

0.001

Percentile

38.4%

An integer overflow exists in Mapbox’s closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes, potentially crashing the Mapbox process.

CNA Affected

[
  {
    "product": "Mapbox",
    "vendor": "Mapbox",
    "versions": [
      {
        "lessThan": "10.6.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.001

Percentile

38.4%

Related for CVELIST:CVE-2022-38216