PT-2017-6566 · Sandstorm · Sandstorm Cap'N Proto

Ben Laurie

·

Published

2017-08-09

·

Updated

2019-12-11

·

CVE-2015-2310

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Sandstorm Cap'n Proto versions prior to 0.4.1.1 Sandstorm Cap'n Proto versions 0.5.x prior to 0.5.1.1
Description The issue is related to an integer overflow in the layout.c++ file, which can be exploited by remote peers via a crafted message. This could lead to a denial of service or potentially allow access to sensitive information from memory, due to inadequate pointer validation.
Recommendations For Sandstorm Cap'n Proto versions prior to 0.4.1.1, update to version 0.4.1.1 or later. For Sandstorm Cap'n Proto versions 0.5.x prior to 0.5.1.1, update to version 0.5.1.1 or later.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2310

Affected Products

Sandstorm Cap'N Proto