PT-2024-4416 · Amazon · Freertos-Plus-Tcp
Ampaschal
+1
·
Published
2024-06-24
·
Updated
2024-06-27
·
CVE-2024-38373
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0
Description
The issue is related to a buffer over-read in the DNS Response Parser of the FreeRTOS-Plus-TCP stack when parsing domain names in a DNS response. A carefully crafted DNS response with a domain name length value greater than the actual domain name length could cause the parser to read beyond the DNS response buffer. This affects applications using the DNS functionality of the FreeRTOS-Plus-TCP stack. Applications not using DNS functionality are not affected.
Recommendations
For FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0, update to version 4.1.1 to resolve the issue. As a temporary workaround, consider disabling the DNS functionality until a patch is available. Restrict access to the DNS Response Parser to minimize the risk of exploitation. Avoid using the DNS functionality in the affected API endpoints until the issue is resolved.
Exploit
Fix
Buffer Over-read
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freertos-Plus-Tcp