Buffer over-read vulnerability in the dtls_sha256_update function in Contiki-NG tinyDTLS through master branch 53a0d97 allows remote attackers to cause a denial of service via crafted data packet.
The attacker sends a crafted data packet to a device using tinyDTLS. The dtls_sha256_update function improperly handles input data, resulting in reading data beyond the allocated buffer boundary (buffer over-read, CWE-125). This results in abnormal process termination or system instability, leading to denial of service.
An unauthenticated remote attacker can cause a denial of service (DoS) on a device using the vulnerable library. The vulnerability may also lead to unauthorized reading of process memory fragments (information disclosure).
Apply patches available from the vendor according to references. It is recommended to update the tinyDTLS library to a version containing a fix for the dtls_sha256_update function. Until an update is applied, restrict network access to devices using the vulnerable library.
Contiki-NG tinyDTLS — master branch up to and including commit 53a0d97
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HContiki Ng Tinydtls
APPContiki-Ng2018-08-30
Related vulnerabilities
Nieskończona pętla i buffer over-read w Contiki-NG tinyDTLS (DTLS ClientHello)
Nieprawidłowa obsługa dużego numeru epoki w Contiki-NG tinyDTLS — DoS i fałszywe odrzucanie pakietów
Błąd obsługi handshake DTLS w Contiki-NG tinyDTLS — denial of service
An assertion failure discovered in in check_certificate_request() in Contiki-NG tinyDTLS through master branch...
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attack...