PT-2018-17835 · Ccn-Lite · Ccn-Lite

Blacksheeep

·

Publicado

2018-02-13

·

Atualizado

2018-03-16

·

CVE-2018-6948

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CCN-lite version 2
Description The issue arises in the ccnl prefix to str detailed function, which can cause a buffer overflow when writing a prefix to the buffer buf. The buffer size is defined as CCNL MAX PREFIX SIZE, but when NFN is enabled, additional characters such as "NFN" and "R2C" tags are written to the buffer, potentially causing an overflow. This can occur when sending an NFN-R2C packet with a prefix of size CCNL MAX PREFIX SIZE.
Recommendations For CCN-lite version 2, consider disabling NFN support to prevent the buffer overflow in the ccnl prefix to str detailed function until a patch is available. Restrict access to the ccnl prefix to str detailed function to minimize the risk of exploitation. Avoid using the buf buffer with NFN-R2C packets that have a prefix of size CCNL MAX PREFIX SIZE until the issue is resolved.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-6948

Produtos afetados

Ccn-Lite