Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78hf-2qv8-j9h7

Опубликовано: 04 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.

NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.

EPSS

Процентиль: 63%
0.00454
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7.3
nvd
почти 4 года назад

NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.

EPSS

Процентиль: 63%
0.00454
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-190