CVE-2021-33889: Buffer Overflow
Published Jul 2, 2021
·Updated
OpenThread wpantund through 2021-07-02 has a stack-based Buffer Overflow because of an inconsistency in the integer data type for metriclen.
Affected Software
1 affected component
Openthread wpantund<=2021-07-02
Remediation
Patch Available
Event History
Jul 2, 2021
CVE Published
via MITRE·06:34 PM
Data Sourced
via MITRE·06:34 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-33889?
CVE-2021-33889 is considered to have a high severity due to the potential for remote code execution from a stack-based buffer overflow.
2
How do I fix CVE-2021-33889?
To fix CVE-2021-33889, you should update OpenThread wpantund to a version released after July 2, 2021.
3
What causes CVE-2021-33889?
CVE-2021-33889 is caused by an inconsistency in the integer data type for metric_len leading to a stack-based buffer overflow.
4
Which versions of wpantund are affected by CVE-2021-33889?
CVE-2021-33889 affects all versions of OpenThread wpantund up to and including 2021-07-02.
5
What are the potential impacts of CVE-2021-33889?
The potential impacts of CVE-2021-33889 include arbitrary code execution, which can compromise system integrity and confidentiality.