CVE-2019-12263: Buffer Overflow
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12263?
CVE-2019-12263 is rated as a critical severity vulnerability due to its potential to cause a buffer overflow in the TCP component of Wind River VxWorks.
How do I fix CVE-2019-12263?
To mitigate CVE-2019-12263, users should apply the latest patches and updates provided by Wind River for affected versions of VxWorks.
Which versions of Wind River VxWorks are affected by CVE-2019-12263?
CVE-2019-12263 affects Wind River VxWorks versions 6.5 through 6.9.4.12 and version 7.0.
What type of vulnerability is CVE-2019-12263?
CVE-2019-12263 is a buffer overflow vulnerability stemming from a race condition in the TCP Urgent Pointer handling.
Are there any workarounds for CVE-2019-12263?
As a temporary measure, restricting network access or disabling services that rely on the TCP URG flag could mitigate risks related to CVE-2019-12263.