CVE-2017-8289: Buffer Overflow
Stack-based buffer overflow in the ipv6addrfromstr function in sys/net/networklayer/ipv6/addr/ipv6addrfromstr.c in RIOT prior to 2017-04-25 allows local attackers, and potentially remote attackers, to cause a denial of service or possibly have unspecified other impact via a malformed IPv6 address.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8289?
CVE-2017-8289 is classified as a high-severity vulnerability due to its potential to cause denial of service and other unspecified impacts.
How do I fix CVE-2017-8289?
To fix CVE-2017-8289, upgrade to a version of RIOT OS released after April 25, 2017.
Who is affected by CVE-2017-8289?
CVE-2017-8289 affects users of RIOT OS prior to version 2017.04.25.
What type of attack is possible with CVE-2017-8289?
CVE-2017-8289 allows local and potentially remote attackers to exploit a stack-based buffer overflow.
What function is vulnerable in CVE-2017-8289?
The vulnerability in CVE-2017-8289 is located in the ipv6_addr_from_str function.