CVE-2019-6963: Buffer Overflow
Published Jun 20, 2019
·Updated
A heap-based buffer overflow in cosadhcpv4dml.c in the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve remote code execution by crafting a long buffer in the "Comment" field of an IP reservation form in the admin panel. This is related to the CcspCommonLibrary module.
Affected Software
1 affected component
Rdkcentral Rdkb Ccsppandm=rdkb-20181217-1
Event History
Jun 20, 2019
CVE Published
via MITRE·01:47 PM
Data Sourced
via MITRE·01:47 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2019-6963.
2
What is the severity of CVE-2019-6963?
The severity of CVE-2019-6963 is high (8.8/10).
3
How does CVE-2019-6963 allow remote code execution?
CVE-2019-6963 allows remote code execution by crafting a long buffer in the "Comment" field of an IP reservation form in the admin panel.
4
What software is affected by CVE-2019-6963?
The RDK RDKB-20181217-1 CcspPandM module is affected by CVE-2019-6963.
5
Is there a fix available for CVE-2019-6963?
There is no information available about a fix for CVE-2019-6963 at this time.