PT-2020-14923 · Readytalk · Readytalk Avian
Pietro Oliva
·
Published
2020-08-12
·
Updated
2024-08-04
·
CVE-2020-17361
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ReadyTalk Avian version 1.2.0
Description
An issue was discovered in the
vm::arrayCopy method defined in classpath-common.h, which returns silently when a negative length is provided, instead of throwing an exception. This could result in data being lost during the copy, with varying consequences depending on the subsequent use of the destination buffer. The issue only affects products that are no longer supported by the maintainer.Recommendations
For ReadyTalk Avian version 1.2.0, consider disabling the
vm::arrayCopy method until a patch is available, or apply alternative mitigation measures to prevent potential data loss.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Readytalk Avian