CVE-2019-1000006

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
04/02/2019
Last modified:
21/07/2021

Description

RIOT RIOT-OS version after commit 7af03ab624db0412c727eed9ab7630a5282e2fd3 contains a Buffer Overflow vulnerability in sock_dns, an implementation of the DNS protocol utilizing the RIOT sock API that can result in Remote code executing. This attack appears to be exploitable via network connectivity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:riot-os:riot:*:*:*:*:*:*:*:* 2017.04 (including) 2018.10.1 (excluding)


References to Advisories, Solutions, and Tools