CVE-2020-24335

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
5
MEDIUM
Affected
3
PROJECTS

Description

An issue was discovered in uIP through 1.0, as used in Contiki and Contiki-NG. Domain name parsing lacks bounds checks, allowing an attacker to corrupt memory with crafted DNS packets.

Contiki-NG: The OS for Next Generation IoT Devices
GitHubGitHub
1.5K
The historical uIP sources
GitHubGitHub
1.07K
The official git repository for Contiki, the open source OS for the Internet of Things
GitHubGitHub
3.8K