CVE-2022-38668

HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfilling a request for a static file smaller than 16 KB.
References
Link Resource
https://github.com/0xhebi/CVEs/blob/main/Crow/CVE-2022-38668.md Exploit Third Party Advisory
https://github.com/CrowCpp/Crow/pull/523 Third Party Advisory
https://gynvael.coldwind.pl/?id=752 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:crowcpp:crow:1.0\+4:*:*:*:*:*:*:*

History

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-200 CWE-908

01 Oct 2022, 02:33

Type Values Removed Values Added
References (MISC) https://github.com/0xhebi/CVEs/blob/main/Crow/CVE-2022-38668.md - (MISC) https://github.com/0xhebi/CVEs/blob/main/Crow/CVE-2022-38668.md - Exploit, Third Party Advisory
References (MISC) https://gynvael.coldwind.pl/?id=752 - (MISC) https://gynvael.coldwind.pl/?id=752 - Exploit, Third Party Advisory

23 Sep 2022, 15:15

Type Values Removed Values Added
References
  • (MISC) https://gynvael.coldwind.pl/?id=752 -
  • (MISC) https://github.com/0xhebi/CVEs/blob/main/Crow/CVE-2022-38668.md -
Summary HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive data from stack memory when fulfilling a request for a static file smaller than 16 KB. HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfilling a request for a static file smaller than 16 KB.

25 Aug 2022, 16:19

Type Values Removed Values Added
References (MISC) https://github.com/CrowCpp/Crow/pull/523 - (MISC) https://github.com/CrowCpp/Crow/pull/523 - Third Party Advisory
CPE cpe:2.3:a:crowcpp:crow:1.0\+4:*:*:*:*:*:*:*
CWE CWE-200
First Time Crowcpp crow
Crowcpp
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

22 Aug 2022, 20:45

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-22 20:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-38668

Mitre link : CVE-2022-38668

CVE.ORG link : CVE-2022-38668


JSON object : View

Products Affected

crowcpp

  • crow
CWE
CWE-908

Use of Uninitialized Resource