oss-sec mailing list archives

CVE-2020-17528: Apache NuttX (incubating) Out of Bound Write from invalid TCP Urgent length


From: Brennan Ashton <btashton () apache org>
Date: Wed, 09 Dec 2020 08:01:39 -0800

Description:
Out-of-bounds Write vulnerability in TCP stack of Apache Software
Foundation Apache NuttX (incubating) allows attacker to corrupt memory
by supplying arbitrary urgent data pointer offsets within TCP packets
including beyond the length of the packet.

This issue affects:
Apache Software Foundation Apache NuttX (incubating) versions prior to
9.1.1 AND 10.0.0.

This issue is also known as AMNESIA:33 CVE-2020-17437

Credit:
Apache NuttX would like to thank Forescout for reporting the issue

Thanks you,
Brennan Ashton


Current thread: