Описание
In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual component length, which has a resultant buffer overflow and out-of-bounds memory accesses.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:ccn-lite:ccn-lite:2.0.0:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00436
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-119
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual component length, which has a resultant buffer overflow and out-of-bounds memory accesses.
EPSS
Процентиль: 62%
0.00436
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-119