CRITICAL 9.8 Maven
Use of Externally-Controlled Format String in wire-avs
GHSA-2j6v-xpf3-xvrv · CVE-2021-41193
Published · Modified
Description
Impact
A remote format string vulnerability allowed an attacker to cause a denial of service or possibly execute arbitrary code.
Patches
- The issue has been fixed in wire-avs 7.1.12 and is already included on all Wire products (currently used version is 8.0.x)
Workarounds
- No workaround known
References
For more information
If you have any questions or comments about this advisory feel free to email us at vulnerability-report@wire.com
Ready to move
Start Securing
Free, no credit card | First findings in minutes