First published: Thu Aug 29 2019(Updated: )
Use After Free vulnerability in the Zephyr shell allows a serial or telnet connected user to cause denial of service, and possibly remote code execution. This issue affects: Zephyr shell versions prior to 1.14.0 on all.
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyrproject Zephyr | <1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14201 is a use after free vulnerability in the Zephyr shell, which allows a serial or telnet connected user to cause denial of service and possible remote code execution.
Versions of Zephyr shell prior to 1.14.0 are affected by CVE-2017-14201.
CVE-2017-14201 has a severity rating of 7.8 (high).
To fix CVE-2017-14201, update Zephyr shell to version 1.14.0 or later.
More information about CVE-2017-14201 can be found at the official Zephyr Project documentation and the related GitHub pull request and issue.