IOWOW is a C utility library and persistent key/value storage engine. Versions 1.4.15 and prior contain a stack buffer overflow vulnerability that allows for Denial of Service (DOS) when it parses scientific notation numbers present in JSON. A patch for this issue is available at commit a79d31e4cff1d5a08f665574b29fd885897a28fd in the `master` branch of the repository. There are no workarounds other than applying the patch.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00063}

epss

{'score': 0.00079}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-22T17:18:13.607Z

Reserved: 2022-01-19T00:00:00.000Z

Link: CVE-2022-23462

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-10-21T22:15:09.540

Modified: 2024-11-21T06:48:36.507

Link: CVE-2022-23462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.