Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4)
Published Aug 9, 2019
9.8
CRITICALCVSS 3.1
EPSS 8.97%
Description
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.
Affected products
No data.
Configuration 2
- ≥ 5.9.0.0 · ≤ 5.9.0.7
- ≥ 5.9.1.0. · ≤ 5.9.1.12
- ≥ 6.2.0.0 · ≤ 6.2.3.1
- ≥ 6.2.4.0 · ≤ 6.2.4.3
- ≥ 6.2.5.0 · ≤ 6.2.5.3
- ≥ 6.2.6.0 · ≤ 6.2.6.1
- ≥ 6.2.7.0 · ≤ 6.2.7.4
- ≥ 6.2.9.0 · ≤ 6.2.9.2
- ≥ 6.5.0.0 · ≤ 6.5.0.3
- ≥ 6.5.1.0 · ≤ 6.5.1.4
- ≥ 6.5.2.0 · ≤ 6.5.2.3
- ≥ 6.5.3.0 · ≤ 6.5.3.3
- ≥ 6.5.4.0. · ≤ 6.5.4.3
- 6.2.7.0
- 6.2.7.1
- 6.2.7.7
Configuration 3
- < 7.59
Running on/with
- n/a
Configuration 4
- ≥ 8.00 · ≤ 8.40.50.00
Configuration 5
- < 7.91
Running on/with
- n/a
Configuration 6
- < 2.2.1
Running on/with
- n/a
Configuration 7
- n/a
Running on/with
- n/a
Configuration 8
- < bs5.2.461.17
Running on/with
- n/a
Configuration 9
- < bs5.2.461.17
Running on/with
- n/a
Configuration 10
- < bs5.2.461.17
Running on/with
- n/a
Configuration 11
- < bs5.2.461.17
Running on/with
- n/a
Configuration 12
- ≥ 46.6.0 · ≤ 46.8.2
Configuration 13
- ≤ 07.0.07
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 14
- ≤ 07.5.01
Running on/with
- n/a
- n/a
Configuration 15
- ≤ 07.2.04
Running on/with
- n/a
- n/a
Configuration 16
- ≤ 05.3.06
Running on/with
- n/a
- n/a
- n/a
Configuration 17
- ≤ 1.0.1_y7
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdf x_refsource_CONFIRMThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdf x_refsource_CONFIRMThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdf x_refsource_CONFIRMThird Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0009 x_refsource_CONFIRMThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190802-0001/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K41190253 x_refsource_CONFIRMThird Party Advisory
- https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12261 x_refsource_MISCVendor Advisory
- https://support2.windriver.com/index.php?page=security-notices x_refsource_MISCIssue TrackingVendor Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCThird Party Advisory
- https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/ x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.