CVE-2017-8289

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-8289
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8289.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-8289
Published
2017-04-27T01:59:02Z
Modified
2024-05-14T06:11:34.492509Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Stack-based buffer overflow in the ipv6addrfromstr function in sys/net/networklayer/ipv6/addr/ipv6addrfrom_str.c in RIOT prior to 2017-04-25 allows local attackers, and potentially remote attackers, to cause a denial of service or possibly have unspecified other impact via a malformed IPv6 address.

References

Affected packages

Git / github.com/riot-os/riot

Affected ranges

Type
GIT
Repo
https://github.com/riot-os/riot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

2013.*

2013.08

2014.*

2014.01
2014.05
2014.12

2015.*

2015.09-RC1
2015.12-RC1
2015.12-devel

2016.*

2016.03-devel
2016.04-RC1
2016.07-RC1
2016.07-RC2
2016.07-devel
2016.10-RC1
2016.10-devel

2017.*

2017.01-devel