CVE-2022-2061

NameCVE-2022-2061
DescriptionHeap-based Buffer Overflow in GitHub repository hpjansson/chafa prior to 1.12.0.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chafa (PTS)buster1.0.1-2vulnerable (unimportant)
bullseye1.6.0-1vulnerable (unimportant)
bookworm1.12.4-1fixed
trixie1.14.0-1fixed
sid1.14.0-1.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chafasource(unstable)1.12.1-1unimportant

Notes

https://github.com/hpjansson/chafa/commit/e6ce3746cdcf0836b9dae659a5aed15d73a080d8
https://huntr.dev/bounties/365ab61f-9a63-421c-97e6-21d4653021f0/
Crash in CLI tool, no security impact

Search for package or bug name: Reporting problems