PT-2020-11890 · Zephyr · Zephyr

Gerson Fernando Budke

+1

·

Published

2020-05-11

·

Updated

2021-10-18

·

CVE-2020-10060

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions zephyrproject-rtos zephyr versions 2.1.0 through 2.2.0 and later versions.
Description The issue occurs after JSON parsing is complete in updatehub probe, where accessing objects[1] from the output structure can lead to referencing uninitialized stack memory if the JSON contains less than two elements. This could result in a crash, denial of service, or possibly an information leak. The attack requires server compromise if the fix for the related issue is applied.
Recommendations For zephyr versions 2.1.0 and later, apply the fix provided to prevent accessing uninitialized stack memory. For zephyr version 2.2.0 and later, ensure the fix is applied to mitigate the risk of a crash, denial of service, or information leak.

Fix

Access of Uninitialized Pointer

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10060

Affected Products

Zephyr