PT-2018-11452 · Ccn-Lite · Ccn-Lite
Blacksheeep
·
Publicado
2018-06-26
·
Atualizado
2020-08-24
·
CVE-2018-12889
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CCN-lite version 2.0.1
Description
An issue was discovered in the handling of binary CCNx or NDN files, where a heap-based buffer overflow occurs due to an array lacking '0' termination. This can result in heap corruption. The issue is related to the
mkAddToRelayCacheRequest and ccnl populate cache functions.Recommendations
For CCN-lite version 2.0.1, the issue was addressed by fixing the memory management in
mkAddToRelayCacheRequest in ccn-lite-ctrl.c. Update the affected function to resolve the issue.Exploit
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ccn-Lite