In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution.
2022-08-03T14:15:08.667
2024-11-21T07:06:07.250
Modified
CVSSv3.1: 8.1 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | intel | connman | ≤ 1.41 | Yes |
| Operating System | debian | debian_linux | 11.0 | Yes |