PT-2023-24672 · Unknown · Contiki-Ng

Ampaschal

+2

·

Published

2023-06-14

·

Updated

2023-06-23

·

CVE-2023-34101

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Contiki-NG versions prior to 4.9
Description The issue arises when the Contiki-NG OS processes ICMP DAO packets in the dao input storing function without verifying that the packet buffer is sufficiently large, leading to potential out-of-bounds reads of up to 16 bytes. An attacker can exploit this by truncating an ICMP packet, causing the system to access data beyond the buffer's bounds.
Recommendations For Contiki-NG versions prior to 4.9, apply the changes in Contiki-NG pull request #2435 to patch the system. For version 4.9 and later, no action is required as the issue is expected to be resolved in this release.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2023-34101
GHSA-FP66-FF6X-7W2W

Affected Products

Contiki-Ng