An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOracle Communications Eagle
APPOracle46.7.046.8.0 – 46.8.246.9.1 – 46.9.3Windriver Vxworks
OSWindriver6.9.4.126.9 – 6.9.4.12 (excl.)7.0 – 21.03 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2021-29999CRITICAL9.8PL ✓same product
Stack overflow w serwerze DHCP systemu Wind River VxWorks
CVE-2021-29998CRITICAL9.8PL ✓same product
Heap overflow w kliencie DHCP systemu Wind River VxWorks
CVE-2016-20009CRITICAL9.8PL ✓same product
Stack-based buffer overflow w kliencie DNS Wind River VxWorks
CVE-2020-10288CRITICAL9.8PL ✓same product
ABB IRC5 — pomijanie uwierzytelnienia na serwerze FTP (port 21)
CVE-2019-12262CRITICAL9.8PL ✓same product
Wind River VxWorks — błąd logiczny w kliencie RARP (nieproszone odpowiedzi)