CVE-2022-38668

HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfilling a request for a static file smaller than 16 KB.
References
Link Resource
https://github.com/CrowCpp/Crow/pull/523 Third Party Advisory
https://github.com/0xhebi/CVEs/blob/main/Crow/CVE-2022-38668.md Exploit Third Party Advisory
https://gynvael.coldwind.pl/?id=752 Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:crowcpp:crow:1.0+4:*:*:*:*:*:*:*

Information

Published : 2022-08-22 08:15

Updated : 2022-10-01 02:33


NVD link : CVE-2022-38668

Mitre link : CVE-2022-38668

Products Affected
No products.
CWE