CVE-2020-28895

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
03/02/2021
Last modified:
12/05/2022

Description

In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:windriver:vxworks:*:*:*:*:*:*:*:* 6.9 (including) 6.9.4.12 (excluding)
cpe:2.3:o:windriver:vxworks:6.9.4.12:-:*:*:*:*:*:*
cpe:2.3:o:windriver:vxworks:6.9.4.12:rolling_cumulative_patch_layer1:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_eagle:*:*:*:*:*:*:*:* 46.8.0 (including) 48.6.2 (including)
cpe:2.3:a:oracle:communications_eagle:*:*:*:*:*:*:*:* 46.9.1 (including) 46.9.3 (including)
cpe:2.3:a:oracle:communications_eagle:46.7.0:*:*:*:*:*:*:*