An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The TCP input data processing function in pico_tcp.c does not validate the length of incoming TCP packets, which leads to an out-of-bounds read when assembling received packets into a data segment, eventually causing Denial-of-Service or an information leak.
References
Link | Resource |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01 | Third Party Advisory US Government Resource |
https://www.kb.cert.org/vuls/id/815128 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-12-11 15:15
Updated : 2020-12-14 13:26
NVD link : CVE-2020-24341
Mitre link : CVE-2020-24341
JSON object : View
CWE
CWE-125
Out-of-bounds Read
Products Affected
altran
- picotcp
- picotcp-ng