CVE-2018-16601: Integer Underflow
Published Dec 6, 2018
·Updated
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. A crafted IP header triggers a full memory space copy in prvProcessIPPacket, leading to denial of service and possibly remote code execution.
Affected Software
2 affected components
Amazon Amazon Web Services Freertos<=1.3.1
Amazon FreeRTOS<=10.0.1
Event History
Dec 6, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16601?
The severity of CVE-2018-16601 is high, with a CVSS score of 8.1.
2
How does CVE-2018-16601 impact Amazon Web Services (AWS) FreeRTOS?
CVE-2018-16601 can lead to denial of service and potentially remote code execution in AWS FreeRTOS.
3
What versions of Amazon Web Services (AWS) FreeRTOS are affected by CVE-2018-16601?
Amazon Web Services (AWS) FreeRTOS versions up to 1.3.1 are affected by CVE-2018-16601.
4
How can I fix CVE-2018-16601?
To fix CVE-2018-16601, it is recommended to update to a patched version of AWS FreeRTOS.
5
Where can I find more information about CVE-2018-16601?
More information about CVE-2018-16601 can be found in the provided references.