PT-2022-23144 · Unknown · Contiki-Ng

·

CVE-2022-36052

·

Published

2022-09-01

·

Updated

2022-09-07

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Contiki-NG versions prior to 4.8
Description The 6LoWPAN implementation in Contiki-NG may cast a UDP header structure at a certain offset in a packet buffer without checking if the packet buffer is large enough to fit a full UDP header structure from the offset where the casting is made. This can cause an out-of-bounds read beyond the packet buffer. The issue affects devices running Contiki-NG that may receive 6LoWPAN packets from external parties.
Recommendations For Contiki-NG versions prior to 4.8, update to Contiki-NG version 4.8 to resolve the issue. As a temporary workaround, consider restricting the reception of 6LoWPAN packets from external parties until the update is applied.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-36052
GHSA-VWR8-6MQV-X7F5

Affected Products

Contiki-Ng