CVE-2015-7599: Integer Overflow
Integer overflow in the authenticate function in svcauth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol is enabled, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a username and password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7599?
CVE-2015-7599 has a high severity rating due to the potential for remote code execution or denial of service.
How do I fix CVE-2015-7599?
To fix CVE-2015-7599, you should update to a patched version of Wind River VxWorks that addresses this integer overflow vulnerability.
What are the affected versions of Wind River VxWorks for CVE-2015-7599?
The affected versions of Wind River VxWorks for CVE-2015-7599 include 5.5, and versions 6.4 through 6.9.4.1.
What type of attacks can CVE-2015-7599 facilitate?
CVE-2015-7599 can facilitate denial of service attacks or potentially allow remote attackers to execute arbitrary code.
Is there a workaround for CVE-2015-7599?
There are no specific workarounds for CVE-2015-7599 other than upgrading to a secure version.