#VU59117 Out-of-bounds read in Contiki OS and uIP - CVE-2020-13987
Published: December 29, 2021
Contiki OS
uIP
contiki-os.org
Adam Dunkels
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.
A remote attacker can send specially crafted traffic to the system, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.