Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gcq-2grw-gh92

Опубликовано: 04 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow.

eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow.

EPSS

Процентиль: 40%
0.00182
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 4.6
nvd
почти 4 года назад

eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow.

EPSS

Процентиль: 40%
0.00182
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-190