CVE-2021-27417: eCosCentric eCosPro RTOS Integer Overflow or Wraparound
eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27417?
CVE-2021-27417 has a high severity due to its potential for heap-based buffer overflow leading to arbitrary code execution.
How do I fix CVE-2021-27417?
To mitigate CVE-2021-27417, update the affected software versions to the latest patches provided by the vendors.
Which software is affected by CVE-2021-27417?
CVE-2021-27417 affects multiple RTOS products, including eCosCentric eCosPro, Amazon FreeRTOS, and ARM Mbed OS among others.
What happens if CVE-2021-27417 is exploited?
Exploitation of CVE-2021-27417 can allow an attacker to execute arbitrary code on the affected system due to improper memory allocation.
Is CVE-2021-27417 exploitability tested?
Yes, CVE-2021-27417 has been assessed and found to be relatively easy to exploit, increasing the urgency for remediation.