CVE-2019-18960

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
11/12/2019
Last modified:
13/09/2022

Description

Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:amazon:firecracker:0.18.0:*:*:*:*:*:*:*
cpe:2.3:a:amazon:firecracker:0.19.0:*:*:*:*:*:*:*