CVE-2023-0779: net: shell: Improper input validation
Published May 30, 2023
·Updated
At the most basic level, an invalid pointer can be input that crashes the device, but with more knowledge of the device’s memory layout, further exploitation is possible.
Affected Software
1 affected component
zephyrproject zephyr<=3.2.0
Event History
May 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
09:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-0779?
The severity of CVE-2023-0779 is high, with a severity value of 7.7.
2
How does CVE-2023-0779 affect Zephyrproject Zephyr?
CVE-2023-0779 affects Zephyrproject Zephyr up to version 3.2.0.
3
How can CVE-2023-0779 be exploited?
CVE-2023-0779 can be exploited by inputting an invalid pointer that crashes the device, and with knowledge of the device's memory layout, further exploitation is possible.
4
Is there a fix available for CVE-2023-0779?
Yes, a fix for CVE-2023-0779 is available. Please refer to the provided reference link for more information.
5
Where can I find more information about CVE-2023-0779?
More information about CVE-2023-0779 can be found in the provided reference link.