Описание
Use After Free vulnerability in the Zephyr shell allows a serial or telnet connected user to cause denial of service, and possibly remote code execution. This issue affects: Zephyr shell versions prior to 1.14.0 on all.
Ссылки
- Release NotesVendor Advisory
- PatchThird Party Advisory
- Broken Link
- Release NotesVendor Advisory
- PatchThird Party Advisory
- Broken Link
Уязвимые конфигурации
Конфигурация 1Версия до 1.14.0 (исключая)
cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00698
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-416
CWE-416
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
Use After Free vulnerability in the Zephyr shell allows a serial or telnet connected user to cause denial of service, and possibly remote code execution. This issue affects: Zephyr shell versions prior to 1.14.0 on all.
EPSS
Процентиль: 71%
0.00698
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-416
CWE-416