PT-2018-11452 · Ccn-Lite · Ccn-Lite
Blacksheeep
·
Published
2018-06-26
·
Updated
2020-08-24
·
CVE-2018-12889
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CCN-lite version 2.0.1
Description
An issue was discovered in the handling of binary CCNx or NDN files, where a heap-based buffer overflow occurs due to an array lacking '0' termination. This can result in heap corruption. The issue is related to the
mkAddToRelayCacheRequest and ccnl populate cache functions.Recommendations
For CCN-lite version 2.0.1, the issue was addressed by fixing the memory management in
mkAddToRelayCacheRequest in ccn-lite-ctrl.c. Update the affected function to resolve the issue.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ccn-Lite