CVE-2022-46770
CVSS V2 None
CVSS V3 None
Description
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through 239.255.255.255).
Overview
- CVE ID
- CVE-2022-46770
- Assigner
- cve@mitre.org
- Vulnerability Status
- Modified
- Published Version
- 2022-12-07T20:15:11
- Last Modified Date
- 2023-03-31T17:15:06
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:linuxfoundation:mirage_firewall:*:*:*:*:*:qubesos:*:* | 1 | OR | 0.8.0 | 0.8.4 |
References
Reference URL | Reference Tags |
---|---|
http://packetstormsecurity.com/files/171610/Qubes-Mirage-Firewall-0.8.3-Denial-Of-Service.html | |
https://github.com/mirage/qubes-mirage-firewall/issues/166 | Exploit Patch Third Party Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2022-46770 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-46770 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-12-07 20:17:06 | Added to TrackCVE | |||
2022-12-07 21:16:01 | 2022-12-07T20:15:11.720 | 2022-12-07T20:15:11 | CVE Published Date | updated |
2022-12-07 21:16:01 | 2022-12-07T21:00:47 | CVE Modified Date | updated | |
2022-12-07 21:16:01 | Received | Awaiting Analysis | Vulnerability Status | updated |
2022-12-09 13:23:16 | Awaiting Analysis | Undergoing Analysis | Vulnerability Status | updated |
2022-12-12 17:15:02 | 2022-12-12T16:56:59 | CVE Modified Date | updated | |
2022-12-12 17:15:02 | Undergoing Analysis | Analyzed | Vulnerability Status | updated |
2022-12-12 17:15:02 | CWE-400 | Weakness Enumeration | new | |
2022-12-12 17:15:03 | CPE Information | updated | ||
2023-03-31 21:12:34 | 2023-03-31T17:15:06 | CVE Modified Date | updated | |
2023-03-31 21:12:34 | Analyzed | Modified | Vulnerability Status | updated |
2023-03-31 21:12:35 | References | updated |