CRITICAL🇵🇱 Wersja polska

CVE-2020-35198

CVSS 9.8v3.1pub. 2021-05-12upd. 2024-11-21

An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Oracle Communications Eagle

    APP
    Oracle
    46.7.046.8.0 – 46.8.246.9.1 – 46.9.3
  • Windriver Vxworks

    OS
    Windriver
    6.9.4.126.9 – 6.9.4.12 (excl.)7.0 – 21.03 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-29999CRITICAL9.8PL ✓same product

Stack overflow w serwerze DHCP systemu Wind River VxWorks

CVE-2021-29998CRITICAL9.8PL ✓same product

Heap overflow w kliencie DHCP systemu Wind River VxWorks

CVE-2016-20009CRITICAL9.8PL ✓same product

Stack-based buffer overflow w kliencie DNS Wind River VxWorks

CVE-2020-10288CRITICAL9.8PL ✓same product

ABB IRC5 — pomijanie uwierzytelnienia na serwerze FTP (port 21)

CVE-2019-12262CRITICAL9.8PL ✓same product

Wind River VxWorks — błąd logiczny w kliencie RARP (nieproszone odpowiedzi)