Логотип exploitDog
bind:CVE-2020-17437
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-17437

Количество 11

Количество 11

ubuntu логотип

CVE-2020-17437

около 5 лет назад

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2020-17437

около 5 лет назад

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2020-17437

около 5 лет назад

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2020-17437

около 5 лет назад

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other p ...

CVSS3: 8.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2861-1

больше 3 лет назад

Security update for open-iscsi

EPSS: Низкий
github логотип

GHSA-cfgh-w4j7-hfhp

больше 3 лет назад

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.

CVSS3: 8.2
EPSS: Низкий
fstec логотип

BDU:2021-01270

около 5 лет назад

Уязвимость функции uip_process операционной системы Contiki OS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2806-1

больше 3 лет назад

Security update for open-iscsi

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1164-1

почти 5 лет назад

Security update for open-iscsi

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0663-1

почти 5 лет назад

Security update for open-iscsi

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2021:1517-1

почти 5 лет назад

Recommended update for open-iscsi

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-17437

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.

CVSS3: 8.2
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-17437

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.

CVSS3: 8.2
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-17437

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.

CVSS3: 8.2
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-17437

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other p ...

CVSS3: 8.2
0%
Низкий
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2022:2861-1

Security update for open-iscsi

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cfgh-w4j7-hfhp

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2021-01270

Уязвимость функции uip_process операционной системы Contiki OS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.2
0%
Низкий
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2022:2806-1

Security update for open-iscsi

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:1164-1

Security update for open-iscsi

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:0663-1

Security update for open-iscsi

почти 5 лет назад
suse-cvrf логотип
SUSE-RU-2021:1517-1

Recommended update for open-iscsi

почти 5 лет назад

Уязвимостей на страницу