PageSourceSearch

https://docs-spectrocloud.netlify.app/assets/js/ab0598e1.bb11706c.js

js docs-spectrocloud.netlify.app collected 2026-10-03 10:41:38 UTC 7,027 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["12691"],{408997:function(e,t,i){i.r(t),i.d(t,{frontMatter:()=>l,toc:()=>d,default:()=>h,metadata:()=>r,assets:()=>a,contentTitle:()=>c});var r=JSON.parse('{"id":"security-bulletins/reports/vc-cve-2022-41409","title":"CVE-2022-41409","description":"Lifecycle of CVE-2022-41409","source":"@site/docs/docs-content/security-bulletins/reports/vc-cve-2022-41409.md","sourceDirName":"security-bulletins/reports","slug":"/security-bulletins/reports/vc-cve-2022-41409","permalink":"/security-bulletins/reports/vc-cve-2022-41409","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/security-bulletins/reports/vc-cve-2022-41409.md","tags":[{"inline":true,"label":"security","permalink":"/tags/security"},{"inline":true,"label":"cve","permalink":"/tags/cve"}],"version":"current","lastUpdatedAt":null,"frontMatter":{"sidebar_label":"CVE-2022-41409","title":"CVE-2022-41409","description":"Lifecycle of CVE-2022-41409","sidebar_class_name":"hide-from-sidebar","hide_table_of_contents":false,"toc_max_heading_level":2,"tags":["security","cve"]},"sidebar":"docSidebar","previous":{"title":"CVE-2022-40735","permalink":"/security-bulletins/reports/vc-cve-2022-40735"},"next":{"title":"CVE-2022-41715","permalink":"/security-bulletins/reports/vc-cve-2022-41715"}}'),s=i(474848),n=i(884429);let l={sidebar_label:"CVE-2022-41409",title:"CVE-2022-41409",description:"Lifecycle of CVE-2022-41409",sidebar_class_name:"hide-from-sidebar",hide_table_of_contents:!1,toc_max_heading_level:2,tags:["security","cve"]},c,a={},d=[{value:"CVE Details",id:"cve-details",level:2},{value:"Initial Publication",id:"initial-publication",level:2},{value:"Last Update",id:"last-update",level:2},{value:"Third Party Dependency",id:"third-party-dependency",level:2},{value:"NIST CVE Summary",id:"nist-cve-summary",level:2},{value:"CVE Severity",id:"cve-severity",level:2},{value:"Our Official Summary",id:"our-official-summary",level:2},{value:"Status",id:"status",level:2},{value:"Affected Products & Versions",id:"affected-products--versions",level:2},{value:"Revision History",id:"revision-history",level:2}];function o(e){let t={a:"a",h2:"h2",p:"p",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,n.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(t.h2,{id:"cve-details",children:"CVE Details"}),"\n",(0,s.jsxs)(t.p,{children:["Visit the official vulnerability details page for ",(0,s.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2022-41409",children:"CVE-2022-41409"})," to learn more."]}),"\n",(0,s.jsx)(t.h2,{id:"initial-publication",children:"Initial Publication"}),"\n",(0,s.jsx)(t.p,{children:"10/25/2024"}),"\n",(0,s.jsx)(t.h2,{id:"last-update",children:"Last Update"}),"\n",(0,s.jsx)(t.p,{children:"04/23/2026"}),"\n",(0,s.jsx)(t.h2,{id:"third-party-dependency",children:"Third Party Dependency"}),"\n",(0,s.jsx)(t.p,{children:"libpcre2-8-0"}),"\n",(0,s.jsx)(t.h2,{id:"nist-cve-summary",children:"NIST CVE Summary"}),"\n",(0,s.jsx)(t.p,{children:"Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input."}),"\n",(0,s.jsx)(t.h2,{id:"cve-severity",children:"CVE Severity"}),"\n",(0,s.jsx)(t.p,{children:(0,s.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2022-41409",children:"7.5"})}),"\n",(0,s.jsx)(t.h2,{id:"our-official-summary",children:"Our Official Summary"}),"\n",(0,s.jsx)(t.p,{children:"This flaw was found in PCRE2 (Perl Regular Controlled Expressions), where it is susceptible to an integer overflow vulnerability triggered by a negative repeat value in the pcre2test subject line that causes infinite looping. This flaw allows a remote attacker to pass specially crafted data to the application, initiating an integer overflow and executing a denial of service (DoS) attack."}),"\n",(0,s.jsx)(t.p,{children:"Risk of exploitation of this vulnerability for our products is low, since accessing this command line utility requires attacker to have privileged access to the containers and do not allow arbitrary code to be run on them. Impact of exploitation is also low since containers have a limited attack surface. Third party containers in which this vulnerability is reported do n
1ot have an upstream fix. We will upgrade the images once the upstream fix becomes available."}),"\n",(0,s.jsx)(t.h2,{id:"status",children:"Status"}),"\n",(0,s.jsx)(t.p,{children:"Ongoing"}),"\n",(0,s.jsx)(t.h2,{id:"affected-products--versions",children:"Affected Products & Versions"}),"\n",(0,s.jsxs)(t.table,{children:[(0,s.jsx)(t.thead,{children:(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.th,{children:"Version"}),(0,s.jsx)(t.th,{children:"Palette Enterprise"}),(0,s.jsx)(t.th,{children:"Palette Enterprise Airgap"}),(0,s.jsx)(t.th,{children:"VerteX"}),(0,s.jsx)(t.th,{children:"VerteX Airgap"})]})}),(0,s.jsxs)(t.tbody,{children:[(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"4.8.52"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"4.7.29"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"4.6.41"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"4.5.22"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"4.4.20"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]})]})]}),"\n",(0,s.jsx)(t.h2,{id:"revision-history",children:"Revision History"}),"\n",(0,s.jsx)(t.p,{children:"No revisions available."})]})}function h(e={}){let{wrapper:t}={...(0,n.R)(),...e.components};return t?(0,s.jsx)(t,{...e,children:(0,s.jsx)(o,{...e})}):o(e)}},884429:function(e,t,i){i.d(t,{R:()=>l,x:()=>c});var r=i(296540);let s={},n=r.createContext(s);function l(e){let t=r.useContext(n);return r.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function c(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:l(e.components),r.createElement(n.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.