SB2019082928 - Multiple vulnerabilities in rutantan zephyr
Published: August 29, 2019 Updated: August 9, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2017-14201)
The vulnerability allows a local authenticated user to execute arbitrary code.
Use After Free vulnerability in the Zephyr shell allows a serial or telnet connected user to cause denial of service, and possibly remote code execution. This issue affects: Zephyr shell versions prior to 1.14.0 on all.
2) Buffer overflow (CVE-ID: CVE-2017-14202)
The vulnerability allows a local authenticated user to execute arbitrary code.
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the shell component of Zephyr allows a serial or telnet connected user to cause a crash, possibly with arbitrary code execution. This issue affects: Zephyr shell versions prior to 1.14.0 on all.
Remediation
Install update from vendor's website.