Описание
In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) were missing parameter checks. This could lead to integer wraparound, under-allocations and heap buffer overflows.
Ссылки
- Mailing List
- Mailing List
- ExploitPatchVendor Advisory
- Mailing List
- Mailing List
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.4.0 (исключая)
cpe:2.3:a:eclipse:threadx:*:*:*:*:*:*:*:*
EPSS
Процентиль: 32%
0.00125
Низкий
7.3 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-122
CWE-190
EPSS
Процентиль: 32%
0.00125
Низкий
7.3 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-122
CWE-190