// For flags

CVE-2022-38216

 

Time Line
Published
2024-03-19
Updated
2024-03-19
Firt exploit
2024-03-19
Overview
Descriptions (2)
NVD, NVD
CWE (1)
CWE-190: Integer Overflow or Wraparound
CAPEC (-)
Risk
CVSS Score
7.5 High
SSVC
-
KEV
-
EPSS
0.1%
Affected Products (-)
Vendors (1)
mapbox
Products (1)
maps_software_development_kit
Versions (1)
< 10.6.1
Intel Resources (-)
Advisories (-)
-
Exploits (-)
-
Plugins (-)
-
References (1)
General (1)
github
Exploits & POcs (-)
Patches (-)
Advisories (-)
Summary
Descriptions

An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes, potentially crashing the Mapbox process.

Se presenta un desbordamiento de enteros en la biblioteca de código cerrado gl-native de Mapbox versiones anteriores a 10.6.1, que es incluida con varios productos de Mapbox, incluyendo las bibliotecas de código abierto. El desbordamiento es causado por grandes valores de altura y anchura de la imagen cuando es creada una nueva imagen y permite escrituras fuera de límites, lo que potencialmente puede bloquear el proceso de Mapbox.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-08-12 CVE Reserved
  • 2022-08-16 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-190: Integer Overflow or Wraparound
CAPEC
Threat Intelligence Resources (0)
Security Advisory details:

Select an advisory to view details here.

Select an exploit to view details here.

Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mapbox
Search vendor "Mapbox"
Maps Software Development Kit
Search vendor "Mapbox" for product "Maps Software Development Kit"
< 10.6.1
Search vendor "Mapbox" for product "Maps Software Development Kit" and version " < 10.6.1"
android
Affected