An issue in coap_pdu.c in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.
coap_pdu.c
{ "binaries": [ { "binary_name": "libcoap-1-0", "binary_version": "4.1.2-1" }, { "binary_name": "libcoap-1-0-bin", "binary_version": "4.1.2-1" }, { "binary_name": "libcoap-1-0-dev", "binary_version": "4.1.2-1" } ] }
{ "binaries": [ { "binary_name": "libcoap2", "binary_version": "4.2.1-1" }, { "binary_name": "libcoap2-bin", "binary_version": "4.2.1-1" }, { "binary_name": "libcoap2-dev", "binary_version": "4.2.1-1" } ] }
{ "binaries": [ { "binary_name": "libcoap2", "binary_version": "4.2.1-1build1" }, { "binary_name": "libcoap2-bin", "binary_version": "4.2.1-1build1" }, { "binary_name": "libcoap2-dev", "binary_version": "4.2.1-1build1" } ] }
{ "binaries": [ { "binary_name": "libcoap3", "binary_version": "4.3.0-2build1" }, { "binary_name": "libcoap3-bin", "binary_version": "4.3.0-2build1" }, { "binary_name": "libcoap3-dev", "binary_version": "4.3.0-2build1" } ] }
{ "binaries": [ { "binary_name": "libcoap3-bin", "binary_version": "4.3.4-1.1build4" }, { "binary_name": "libcoap3-dev", "binary_version": "4.3.4-1.1build4" }, { "binary_name": "libcoap3t64", "binary_version": "4.3.4-1.1build4" } ] }