CVE-2022-3715: Buffer Overflow
A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parametertransform. This issue may lead to memory problems.
Other sources
A heap-buffer-overflow in validparametertransform function.
— Red Hat
Bash is vulnerable to a heap-based buffer overflow, caused by improper bounds checking in the validparametertransform function. By opening a specially-crafted file, a local authenticated attacker could overflow a buffer and execute arbitrary code in the context of the current process.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-3715?
CVE-2022-3715 is a vulnerability found in the bash package where a heap-buffer overflow can occur in valid parameter_transform.
What is the severity of CVE-2022-3715?
The severity of CVE-2022-3715 is high with a CVSS score of 7.8.
Which software is affected by CVE-2022-3715?
The bash package with version up to and including 5.1.8, GNU Bash, and Redhat Enterprise Linux version 9.0 are affected by CVE-2022-3715.
How can CVE-2022-3715 lead to memory problems?
CVE-2022-3715 can lead to memory problems due to the heap-buffer overflow that can occur in valid parameter_transform.
How do I fix CVE-2022-3715?
To fix CVE-2022-3715, update the bash package to version 5.1.8 or apply the relevant patch provided by the vendor.