CVE-2020-15350: Buffer Overflow
RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64decode() uses an output buffer estimation function to compute the required buffer capacity and validate against the provided buffer size. The base64estimatedecodesize() function calculates the expected decoded size with an arithmetic round-off error and does not take into account possible padding bytes. Due to this underestimation, it may be possible to craft base64 input that causes a buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15350?
CVE-2020-15350 is categorized as a high severity vulnerability due to the potential for remote code execution resulting from the buffer overflow.
How do I fix CVE-2020-15350?
To fix CVE-2020-15350, update to a patched version of RIOT OS that addresses the buffer overflow in the base64 decoder.
What systems are affected by CVE-2020-15350?
CVE-2020-15350 affects the RIOT OS version 2020.04.
What type of vulnerability is CVE-2020-15350?
CVE-2020-15350 is classified as a buffer overflow vulnerability.
What is the impact of CVE-2020-15350?
The impact of CVE-2020-15350 can lead to denial of service or potential remote code execution, compromising system integrity.