Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xj6g-7vq6-3mcm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue was discovered in HCC Embedded InterNiche NicheStack through 4.3. The tfshnd():tftpsrv.c TFTP packet processing function doesn't ensure that a filename is adequately '\0' terminated; therefore, a subsequent call to strlen for the filename might read out of bounds of the protocol packet buffer (if no '\0' byte exists within a reasonable range).

An issue was discovered in HCC Embedded InterNiche NicheStack through 4.3. The tfshnd():tftpsrv.c TFTP packet processing function doesn't ensure that a filename is adequately '\0' terminated; therefore, a subsequent call to strlen for the filename might read out of bounds of the protocol packet buffer (if no '\0' byte exists within a reasonable range).

EPSS

Процентиль: 57%
0.00353
Низкий

7.5 High

CVSS3

Дефекты

CWE-273

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

An issue was discovered in HCC Embedded InterNiche NicheStack through 4.3. The tfshnd():tftpsrv.c TFTP packet processing function doesn't ensure that a filename is adequately '\0' terminated; therefore, a subsequent call to strlen for the filename might read out of bounds of the protocol packet buffer (if no '\0' byte exists within a reasonable range).

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость реализации функции обработки TFTP-пакетов стеков TCP/IP NicheLite и InterNiche, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 57%
0.00353
Низкий

7.5 High

CVSS3

Дефекты

CWE-273