CVE-2020-17529
Apache NuttX (incubating) Out of Bound Write from invalid fragmentation offset value specified in the IP header
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offset value specified in the IP header. This is only impacts builds with both CONFIG_EXPERIMENTAL and CONFIG_NET_TCP_REASSEMBLY build flags enabled.
Una vulnerabilidad de escritura fuera de límites en la pila TCP de Apache NuttX (incubating) versiones hasta e incluyendo a 9.1.0 y 10.0.0, permite a un atacante corromper la memoria al suministrar un valor de compensación de fragmentación no válido especificado en el encabezado IP. Esto solo afecta a las compilaciones con los indicadores de compilación CONFIG_EXPERIMENTAL y CONFIG_NET_TCP_REASSEMBLY habilitados
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-12 CVE Reserved
- 2020-12-09 CVE Published
- 2024-12-17 EPSS Updated
- 2025-02-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2020/12/09/5 | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Nuttx Search vendor "Apache" for product "Nuttx" | <= 9.1.0 Search vendor "Apache" for product "Nuttx" and version " <= 9.1.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Nuttx Search vendor "Apache" for product "Nuttx" | 10.0.0 Search vendor "Apache" for product "Nuttx" and version "10.0.0" | - |
Affected
|