Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-13987

Опубликовано: 09 дек. 2020
Источник: redhat
CVSS3: 7.5

Описание

An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.

Отчет

Although a vulnerable version of uIP is included in iscsi-initiator-utils, it is believed that the vulnerability can not be actively exploited in that particular context.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5iscsi-initiator-utilsOut of support scope
Red Hat Enterprise Linux 6iscsi-initiator-utilsOut of support scope
Red Hat Enterprise Linux 7iscsi-initiator-utilsFix deferred
Red Hat Enterprise Linux 9iscsi-initiator-utilsNot affected
Red Hat Enterprise Linux 8iscsi-initiator-utilsFixedRHBA-2021:444609.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=1899467Open-iSCSI: OOB read in checksum calculation in uIP

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.

CVSS3: 7.5
nvd
около 5 лет назад

An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.

CVSS3: 7.5
debian
около 5 лет назад

An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read ...

CVSS3: 7.5
github
больше 3 лет назад

An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.

CVSS3: 7.5
fstec
около 5 лет назад

Уязвимость компонента uIP TCP/IP Stack операционной системы Contiki OS, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3