CVE-2020-35198

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
12/05/2021
Last modified:
12/05/2022

Description

An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:windriver:vxworks:*:*:*:*:*:*:*:* 6.9 (including) 6.9.4.12 (excluding)
cpe:2.3:o:windriver:vxworks:*:*:*:*:*:*:*:* 7.0 (including) 21.03 (excluding)
cpe:2.3:o:windriver:vxworks:6.9.4.12:-:*:*:*:*:*:*
cpe:2.3:o:windriver:vxworks:6.9.4.12:rolling_cumulative_patch_layer1:*:*:*:*:*:*
cpe:2.3:o:windriver:vxworks:6.9.4.12:rolling_cumulative_patch_layer2:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_eagle:*:*:*:*:*:*:*:* 46.8.0 (including) 46.8.2 (including)
cpe:2.3:a:oracle:communications_eagle:*:*:*:*:*:*:*:* 46.9.1 (including) 46.9.3 (including)
cpe:2.3:a:oracle:communications_eagle:46.7.0:*:*:*:*:*:*:*