PT-2025-25489 · Apache · Apache Nuttx
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache NuttX versions 6.9 through 12.9.0
Description
An Out-of-bounds Write resulting in a possible Heap-based Buffer Overflow issue was discovered in the tools/bdf-converter font conversion utility, which is part of the Apache NuttX RTOS repository. This utility is optional and not part of the NuttX RTOS or Applications runtime. However, active users of bdf-converter may be affected when the tool is exposed to external user data.
Recommendations
For Apache NuttX versions 6.9 through 12.9.0, upgrade to version 12.9.0 to fix the issue.
Exploit
Fix
Buffer Overflow
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Nuttx