CVE-2020-24338: Critical severity altran picotcp-ng vulnerability
An issue was discovered in picoTCP through 1.7.0. The DNS domain name record decompression functionality in picodnsdecompressname() in picodnscommon.c does not validate the compression pointer offset values with respect to the actual data present in a DNS response packet, causing out-of-bounds writes that lead to Denial-of-Service and Remote Code Execution.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-24338.
What is the severity of CVE-2020-24338?
The severity of CVE-2020-24338 is critical with a CVSS score of 9.8.
What software is affected by CVE-2020-24338?
The affected software is Altran picoTCP version up to and including 1.7.0.
What is the CWE ID for CVE-2020-24338?
The CWE ID for CVE-2020-24338 is CWE-787.
Is there any additional information about CVE-2020-24338?
Yes, you can find more information about CVE-2020-24338 on the following references: [US-CERT Advisory](https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01) and [CERT Vulnerability Note](https://www.kb.cert.org/vuls/id/815128).