First published: Fri Sep 07 2018(Updated: )
An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in parse_relations in os/storage/antelope/aql-parser.c while parsing AQL (storage of relations).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Contiki-ng Contiki-ng. | <=4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16663 is a vulnerability in Contiki-NG, specifically in the parse_relations function of os/storage/antelope/aql-parser.c.
CVE-2018-16663 has a severity of 7.8 (High).
CVE-2018-16663 affects Contiki-NG versions up to and including 4.1.
CVE-2018-16663 is associated with CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-787 (Out-of-bounds Write).
Yes, the issue has been fixed in Contiki-NG version 4.2.0.