CVE-2018-16663: Buffer Overflow
Published Sep 7, 2018
·Updated
An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in parserelations in os/storage/antelope/aql-parser.c while parsing AQL (storage of relations).
Affected Software
1 affected component
Contiki-NG Contiki-ng.<=4.1
Event History
Sep 7, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16663?
CVE-2018-16663 is a vulnerability in Contiki-NG, specifically in the parse_relations function of os/storage/antelope/aql-parser.c.
2
What is the severity of CVE-2018-16663?
CVE-2018-16663 has a severity of 7.8 (High).
3
How does CVE-2018-16663 affect Contiki-NG?
CVE-2018-16663 affects Contiki-NG versions up to and including 4.1.
4
What is the Common Weakness Enumeration (CWE) for CVE-2018-16663?
CVE-2018-16663 is associated with CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-787 (Out-of-bounds Write).
5
Is there a fix available for CVE-2018-16663?
Yes, the issue has been fixed in Contiki-NG version 4.2.0.