PT-2023-24672 · Unknown · Contiki-Ng
Ampaschal
+2
·
Published
2023-06-14
·
Updated
2023-06-23
·
CVE-2023-34101
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Contiki-NG versions prior to 4.9
Description
The issue arises when the Contiki-NG OS processes ICMP DAO packets in the
dao input storing function without verifying that the packet buffer is sufficiently large, leading to potential out-of-bounds reads of up to 16 bytes. An attacker can exploit this by truncating an ICMP packet, causing the system to access data beyond the buffer's bounds.Recommendations
For Contiki-NG versions prior to 4.9, apply the changes in Contiki-NG pull request #2435 to patch the system.
For version 4.9 and later, no action is required as the issue is expected to be resolved in this release.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contiki-Ng