CVE-2020-24340: High severity altran picotcp-ng vulnerability
An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The code that processes DNS responses in picomdnshandledataasanswersgeneric() in picomdns.c does not check whether the number of answers/responses specified in a DNS packet header corresponds to the response data available in the packet, leading to an out-of-bounds read, invalid pointer dereference, and Denial-of-Service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24340?
CVE-2020-24340 is a vulnerability in picoTCP and picoTCP-NG through 1.7.0 that allows an attacker to bypass security restrictions via a crafted DNS packet.
How does CVE-2020-24340 affect Altran picoTCP and Altran Picotcp-ng?
CVE-2020-24340 affects Altran picoTCP and Altran Picotcp-ng versions up to and including 1.7.0.
What is the severity of CVE-2020-24340?
CVE-2020-24340 has a severity rating of 7.5 (high).
How can an attacker exploit CVE-2020-24340?
An attacker can exploit CVE-2020-24340 by sending a crafted DNS packet with a mismatch between the number of answers specified in the packet header and the actual response data.
Is there a fix available for CVE-2020-24340?
Yes, users should update to a version of picoTCP or picoTCP-NG that is higher than 1.7.0 to fix CVE-2020-24340.