Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-39829


There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new.


Published

2022-09-05T04:15:08.790

Last Modified

2024-11-21T07:18:20.437

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application samsung mtower ≤ 0.3.0 Yes

References