#VU29095 Input validation error in TCP/IP stack - CVE-2020-11902
Published: June 17, 2020
TCP/IP stack
Placeful Inc.
Description
The vulnerability allows a remote attacker to gain access to sensitive information or perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in IPv6 over IPv4 tunneling component. A remote attacker can send a specially crafted packet to the application and trigger out-of-bounds read, leading to information disclosure or denial of service condition.