PT-2020-11890 · Zephyr · Zephyr
Gerson Fernando Budke
+1
·
Published
2020-05-11
·
Updated
2021-10-18
·
CVE-2020-10060
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
zephyrproject-rtos zephyr versions 2.1.0 through 2.2.0 and later versions.
Description
The issue occurs after JSON parsing is complete in updatehub probe, where accessing objects[1] from the output structure can lead to referencing uninitialized stack memory if the JSON contains less than two elements. This could result in a crash, denial of service, or possibly an information leak. The attack requires server compromise if the fix for the related issue is applied.
Recommendations
For zephyr versions 2.1.0 and later, apply the fix provided to prevent accessing uninitialized stack memory.
For zephyr version 2.2.0 and later, ensure the fix is applied to mitigate the risk of a crash, denial of service, or information leak.
Fix
Access of Uninitialized Pointer
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zephyr