First published: Mon Jun 19 2023(Updated: )
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 lacks certain size calculations before attempting to set a value of an mss structure member.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PicoTCP | <=2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35848 is a vulnerability in VirtualSquare picoTCP (aka PicoTCP-NG) through version 2.1 that lacks certain size calculations before attempting to set a value of an mss structure member.
The severity of CVE-2023-35848 is high with a severity score of 7.5.
CVE-2023-35848 affects VirtualSquare picoTCP versions up to 2.1 by not performing certain size calculations before attempting to set a value of an mss structure member.
The Common Weakness Enumeration (CWE) for CVE-2023-35848 is CWE-682.
The fix for CVE-2023-35848 can be found at the following link: [GitHub Pull Request](https://github.com/virtualsquare/picotcp/pull/15/files).