HIGH
An issue was discovered in picoTCP 1.7.0
Published Dec 11, 2020
7.5
HIGHCVSS 3.1
EPSS 2.89%
Description
An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 destination options does not check for a valid length of the destination options header. This results in an Out-of-Bounds Read, and, depending on the memory protection mechanism, this may result in Denial-of-Service in pico_ipv6_process_destopt() in pico_ipv6.c.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-9398 Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01 x_refsource_MISCThird Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/815128 x_refsource_MISCThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-9398 | Advisory | |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01 | x_refsource_MISCThird Party AdvisoryUS Government Resource | |
| https://www.kb.cert.org/vuls/id/815128 | x_refsource_MISCThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 11, 2020
Updated Aug 4, 2024
Reserved Aug 7, 2020
Link CVE-2020-17445
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data