CVE-2022-1289

NameCVE-2022-1289
DescriptionA denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. This is due to an incomplete fix of CVE-2022-1211. It is possible to initiate the attack remotely but it requires user interaction. The issue got fixed with the patch 0eb02422d5161767e9983bdaa5c429762d3477ce.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
furnace (PTS)sid, trixie0.6.7+git20241016+ds-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
furnacesource(unstable)(not affected)

Notes

- furnace <not-affected> (No Debian released version affected by CVE-2022-1211)
CVE assigned for incomple fix for CVE-2022-1211.
https://github.com/tildearrow/furnace/issues/325#issuecomment-1094139655

Search for package or bug name: Reporting problems