CVE-2020-13598: FS: Buffer Overflow when enabling Long File Names in FAT_FS and calling fs_stat
Published May 24, 2021
·Updated
FS: Buffer Overflow when enabling Long File Names in FATFS and calling fsstat. Zephyr versions >= v1.14.2, >= v2.3.0 contain Stack-based Buffer Overflow (CWE-121). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7fhv-rgxr-x56h
Affected Software
2 affected components
zephyrproject zephyr<=1.14.2
zephyrproject zephyr>=2.0.0<=2.3.0
Event History
May 24, 2021
CVE Published
via MITRE·09:40 PM
Data Sourced
via MITRE·09:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-13598?
CVE-2020-13598 is a vulnerability that allows a stack-based buffer overflow when enabling long file names in FAT_FS and calling fs_stat in Zephyr versions >= v1.14.2, >= v2.3.0.
2
What is the severity of CVE-2020-13598?
The severity of CVE-2020-13598 is high with a severity value of 7.8.
3
What is the affected software?
The affected software is Zephyrproject Zephyr versions >= v1.14.2, >= v2.3.0.
4
What is the CWE of CVE-2020-13598?
The CWE of CVE-2020-13598 is CWE-121.
5
How do I fix CVE-2020-13598?
To fix CVE-2020-13598, update to a version of Zephyr that is not affected by the vulnerability.