CVE-2018-16666: Buffer Overflow
Published Sep 7, 2018
·Updated
An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in nextstring in os/storage/antelope/aql-lexer.c while parsing AQL (parsing next string).
Affected Software
1 affected component
Contiki-NG Contiki-ng.<=4.1
Event History
Sep 7, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16666?
CVE-2018-16666 is a vulnerability in Contiki-NG through 4.1 that allows for a stack-based buffer overflow in the AQL parser.
2
How severe is CVE-2018-16666?
CVE-2018-16666 has a severity rating of 7.8, which is considered high.
3
What is the affected software version of CVE-2018-16666?
CVE-2018-16666 affects all Contiki-NG versions up to and including 4.1.
4
How can I fix CVE-2018-16666?
To fix CVE-2018-16666, it is recommended to update Contiki-NG to a version beyond 4.1.
5
Where can I find more information about CVE-2018-16666?
More information about CVE-2018-16666 can be found at https://github.com/contiki-ng/contiki-ng/issues/595