PT-2017-17641 · Contiki · Contiki Operating System
Alex Pop
+3
·
Publicado
2017-05-28
·
Atualizado
2017-06-06
·
CVE-2017-7295
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Contiki Operating System version 3.0
Description
A use-after-free issue exists in the httpd-simple.c file of the cc26xx-web-demo httpd, where the http state structure is not properly deallocated upon a connection close event. This results in a NULL pointer dereference in the output processing function, causing a board crash that can be exploited to perform a denial of service.
Recommendations
For Contiki Operating System version 3.0, as a temporary workaround, consider disabling the httpd-simple.c module until a patch is available. Restrict access to the cc26xx-web-demo httpd to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Correção
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Contiki Operating System