openwrt ▾
›
master ▾
›
component
›
confuse
Component Overview
Vulnerability Overview
Name
confuse
Version
3.3-r2
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:libconfuse_project:libconfuse:3.3:*:*:*:*:*:*:*
Other Versions
#
Project
Branch
Version
openwrt
openwrt-25.12
3.3-r2
Patches
#
#
Title
Author
Resolve
1
Fix #163: unterminated username used with getpwnam()
Joachim Wiberg <troglobit@gmail.com>
CVE-2022-40320
Vulnerabilities
#
Name
Analysis
Description
CVE-2022-40320
Patched
cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.