Skip to content

Remote format string vulnerability

High
comawill published GHSA-2j6v-xpf3-xvrv Mar 1, 2022

Package

wire-avs (wire)

Affected versions

<7.1.12

Patched versions

7.1.12

Description

Impact

A remote format string vulnerability allowed an attacker to cause a denial of service or possibly execute arbitrary code.

Patches

  • The issue has been fixed in wire-avs 7.1.12 and is already included on all Wire products (currently used version is 8.0.x)

Workarounds

  • No workaround known

References

For more information

If you have any questions or comments about this advisory feel free to email us at vulnerability-report@wire.com

Severity

High

CVE ID

CVE-2021-41193

Weaknesses