Date: Wed, 09 Dec 2020 08:01:39 -0800 From: Brennan Ashton <btashton@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2020-17528: Apache NuttX (incubating) Out of Bound Write from invalid TCP Urgent length Description: Out-of-bounds Write vulnerability in TCP stack of Apache Software Foundation Apache NuttX (incubating) allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP packets including beyond the length of the packet. This issue affects: Apache Software Foundation Apache NuttX (incubating) versions prior to 9.1.1 AND 10.0.0. This issue is also known as AMNESIA:33 CVE-2020-17437 Credit: Apache NuttX would like to thank Forescout for reporting the issue Thanks you, Brennan Ashton
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.