An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://sourceforge.net/p/ini4j/bugs/56/ | third party advisory exploit mailing list |
https://lists.debian.org/debian-lts-announce/2022/11/msg00037.html | third party advisory mailing list |
https://github.com/Checkmarx/Vulnerabilities-Proofs-of-Concept/tree/main/2022/CVE-2022-41404 |