First published: Thu Dec 06 2018(Updated: )
Amazon Web Services (AWS) FreeRTOS through 1.3.1 has an uninitialized pointer free in SOCKETS_SetSockOpt.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Amazon Web Services Freertos | <=1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16522 is a vulnerability found in Amazon Web Services (AWS) FreeRTOS through version 1.3.1 that allows for an uninitialized pointer free in SOCKETS_SetSockOpt.
CVE-2018-16522 has a severity rating of 8.1, which is considered high.
CVE-2018-16522 affects Amazon Web Services (AWS) FreeRTOS through version 1.3.1 by allowing for an uninitialized pointer free in SOCKETS_SetSockOpt, which can lead to potential security compromise.
Yes, a fix is available for CVE-2018-16522. It is recommended to update to the latest version of Amazon Web Services (AWS) FreeRTOS.
More information about CVE-2018-16522 can be found in the following references: [Link 1](https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-details/), [Link 2](https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-put-wide-range-devices-risk-compromise-smart-homes-critical-infrastructure-systems/), [Link 3](https://github.com/aws/amazon-freertos/blob/v1.3.2/CHANGELOG.md)