PT-2020-14923 · Readytalk · Readytalk Avian

Pietro Oliva

·

Published

2020-08-12

·

Updated

2024-08-04

·

CVE-2020-17361

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ReadyTalk Avian version 1.2.0
Description An issue was discovered in the vm::arrayCopy method defined in classpath-common.h, which returns silently when a negative length is provided, instead of throwing an exception. This could result in data being lost during the copy, with varying consequences depending on the subsequent use of the destination buffer. The issue only affects products that are no longer supported by the maintainer.
Recommendations For ReadyTalk Avian version 1.2.0, consider disabling the vm::arrayCopy method until a patch is available, or apply alternative mitigation measures to prevent potential data loss. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2020-17361

Affected Products

Readytalk Avian