An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service and potentially disclose information via crafted SNMP packets to snmp_ber_decode_string_len_buffer in os/net/app-layer/snmp/snmp-ber.c.
References
Link | Resource |
---|---|
https://github.com/contiki-ng/contiki-ng/commit/12c824386ab60de757de5001974d73b32e19ad71#diff-32367fad664c6118fd5dda77cdf38eedc006cdd7544eca5bbeebe0b99653f8a0 | Patch Third Party Advisory |
https://github.com/contiki-ng/contiki-ng/pull/1355 | Patch Third Party Advisory |
https://twitter.com/ScepticCtf | Third Party Advisory |
https://github.com/contiki-ng/contiki-ng/commit/12c824386ab60de757de5001974d73b32e19ad71#diff-32367fad664c6118fd5dda77cdf38eedc006cdd7544eca5bbeebe0b99653f8a0 | Patch Third Party Advisory |
https://github.com/contiki-ng/contiki-ng/pull/1355 | Patch Third Party Advisory |
https://twitter.com/ScepticCtf | Third Party Advisory |
Configurations
History
21 Nov 2024, 04:59
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/contiki-ng/contiki-ng/commit/12c824386ab60de757de5001974d73b32e19ad71#diff-32367fad664c6118fd5dda77cdf38eedc006cdd7544eca5bbeebe0b99653f8a0 - Patch, Third Party Advisory | |
References | () https://github.com/contiki-ng/contiki-ng/pull/1355 - Patch, Third Party Advisory | |
References | () https://twitter.com/ScepticCtf - Third Party Advisory |
Information
Published : 2021-10-19 16:15
Updated : 2024-11-21 04:59
NVD link : CVE-2020-12141
Mitre link : CVE-2020-12141
CVE.ORG link : CVE-2020-12141
JSON object : View
Products Affected
contiki-ng
- contiki-ng
CWE
CWE-125
Out-of-bounds Read