Logo
vulnerabilityCVE-2022-40320
Name
CVE-2022-40320
Source
NVD ( link)Debian ( link)
Description
cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
confuse
Patched

Vulnerability Rating#


8.8
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.3
Patched
buildroot
master
3.3
Patched
openwrt
openwrt-25.12
3.3-r2
Patched
yocto
kirkstone
3.3
Patched
yocto
master
3.3
Exploitable
yocto
scarthgap
3.3
Exploitable

Resolved with patches#


libconfuse (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Fix #163: unterminated username used with getpwnam()
Joachim Wiberg <troglobit@gmail.com>
CVE-2022-40320

libconfuse (buildroot:master)

#
Title
Author
Resolve
1
Fix #163: unterminated username used with getpwnam()
Joachim Wiberg <troglobit@gmail.com>
CVE-2022-40320

confuse (openwrt:master)

#
Title
Author
Resolve
1
Fix #163: unterminated username used with getpwnam()
Joachim Wiberg <troglobit@gmail.com>
CVE-2022-40320

confuse (openwrt:openwrt-25.12)

#
Title
Author
Resolve
1
Fix #163: unterminated username used with getpwnam()
Joachim Wiberg <troglobit@gmail.com>
CVE-2022-40320

libconfuse (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix #163: unterminated username used with getpwnam()
Joachim Wiberg <troglobit@gmail.com>
CVE-2022-40320