PT-2018-17575 · Ccn-Lite · Ccn-Lite
Mfrey
+1
·
Publicado
2018-01-31
·
Atualizado
2018-02-21
·
CVE-2018-6480
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CCN-lite version 2
Description
A type confusion issue was discovered, leading to a memory access violation and a failure of the nonce feature, which is used for loop prevention. The
ccnl fwd handleInterest function assumes a specific type for the union member s, but if the type is different, the memory is either uninitialised or points to incorrect data, rendering the nonce check insufficient.Recommendations
For CCN-lite version 2, consider modifying the
ccnl fwd handleInterest function to correctly handle different types for the union member s, ensuring that the memory access is valid and the nonce feature functions as intended.Correção
Incorrect Type Conversion or Cast
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ccn-Lite