CVE-2019-20791
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
28/04/2020
Last modified:
17/06/2026
Description
OpenThread before 2019-12-13 has a stack-based buffer overflow in MeshCoP::Commissioner::GeneratePskc.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:google:openthread:*:*:*:*:*:*:*:* | 2019-12-13 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19386
- https://github.com/openthread/openthread/commit/b8c3161281f8e15873f8decabd8eac461717aefe
- https://github.com/openthread/openthread/commit/c3a3a0c424322009fec3ab735fb20ce8f6e19e70
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19386
- https://github.com/openthread/openthread/commit/b8c3161281f8e15873f8decabd8eac461717aefe
- https://github.com/openthread/openthread/commit/c3a3a0c424322009fec3ab735fb20ce8f6e19e70



