Out-of-bounds write in uIP and Contiki OS - CVE-2020-17437

 

Out-of-bounds write in uIP and Contiki OS - CVE-2020-17437

Published: December 29, 2021


Vulnerability identifier: #VU59115
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-17437
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing TCP packets with Urgent flag. A remote attacker can send specially crafted traffic to the system, trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

uIP
Contiki OS
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Legacy Software
Ubuntu
openEuler
open-iscsi (Ubuntu package)
iscsiuio
iscsiuio-debuginfo
open-isns-debuginfo
open-isns
open-iscsi-debugsource
open-iscsi-debuginfo
open-iscsi
libopeniscsiusr0_2_0-debuginfo
libopeniscsiusr0_2_0
open-iscsi-devel
open-iscsi-help
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)

How to mitigate CVE-2020-17437

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

open-iscsi (Ubuntu package) - addressed in versions Ubuntu Pro, 2.0.874-7.1ubuntu6.4
iscsiuio - addressed in versions 0.7.8.2-12.27.2, 0.7.8.2-13.42.1, 0.7.8.2-46.17.2, 0.7.8.2-53.34.1
iscsiuio-debuginfo - addressed in versions 0.7.8.2-12.27.2, 0.7.8.2-13.42.1, 0.7.8.2-46.17.2, 0.7.8.2-53.34.1
open-isns-debuginfo - update to 0.95-46.17.2
open-isns - update to 0.95-46.17.2
open-iscsi-debugsource - addressed in versions 2.0.873-46.17.2, 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
open-iscsi-debuginfo - addressed in versions 2.0.873-46.17.2, 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
open-iscsi - addressed in versions 2.0.873-46.17.2, 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
libopeniscsiusr0_2_0-debuginfo - addressed in versions 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
libopeniscsiusr0_2_0 - addressed in versions 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
open-iscsi-devel - update to 2.0.876-13.42.1
open-iscsi-debuginfo - update to 2.1.1-11
open-iscsi-help - update to 2.1.1-11
open-iscsi-debugsource - update to 2.1.1-11
open-iscsi-devel - update to 2.1.1-11
open-iscsi - update to 2.1.1-11
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007

External References

Related Security Bulletins