Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-1249
HistoryApr 29, 2022 - 12:00 a.m.

CVE-2022-1249

2022-04-2900:00:00
ubuntu.com
ubuntu.com
17
cve-2022-1249
pesign
cms_set_pw_data
unix
null pointer dereference
crash

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

EPSS

0

Percentile

12.6%

A NULL pointer dereference flaw was found in pesign’s cms_set_pw_data()
function of the cms_common.c file. The function fails to handle the NULL
pwdata invocation from daemon.c, which leads to an explicit NULL
dereference and crash on all attempts to daemonize pesign.

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

EPSS

0

Percentile

12.6%