CVE-2022-25867: NULL Pointer Dereference
Published Aug 2, 2022
·Updated
The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format.
Affected Software
1 affected component
Socket Socket.io-client Java<2.0.1
Remediation
Patch Available
Event History
Aug 2, 2022
CVE Published
via MITRE·01:28 PM
Data Sourced
via MITRE·01:28 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-25867.
2
What is the severity of CVE-2022-25867?
The severity of CVE-2022-25867 is high with a severity value of 7.5.
3
What is affected software by CVE-2022-25867?
The affected software by CVE-2022-25867 is the package io.socket:socket.io-client before version 2.0.1.
4
What is the description of CVE-2022-25867?
CVE-2022-25867 is a vulnerability in the package io.socket:socket.io-client before 2.0.1 that allows for a NULL pointer dereference when parsing a packet with an invalid payload format.
5
How can I fix CVE-2022-25867?
To fix CVE-2022-25867, it is recommended to update the package io.socket:socket.io-client to version 2.0.1 or later.