CVE-2020-13988: Integer Overflow
An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsing TCP MSS options of IPv4 network packets in uipprocess in net/ipv4/uip.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2020-13988.
What is the severity level of CVE-2020-13988?
The severity level of CVE-2020-13988 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2020-13988?
The affected software versions for CVE-2020-13988 include Contiki through version 3.0 and open-iscsi versions 2.0.874-5ubuntu2.11+ to 2.1.3-1ubuntu1.
How can I fix CVE-2020-13988?
To fix CVE-2020-13988, update to Contiki version 3.0 or later and open-iscsi version 2.1.3-1ubuntu1 or later.
Where can I find more information about CVE-2020-13988?
You can find more information about CVE-2020-13988 at the following references: [1](https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01), [2](https://www.kb.cert.org/vuls/id/815128), [3](https://launchpad.net/bugs/cve/CVE-2020-13988).