-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
Description
prvProcessICMPPacket doesn’t validate that the received frame is large enough to be an ICMP packet, and can access fields from this packet out of bounds.
Root cause
Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow information disclosure during parsing of ICMP packets in prvProcessICMPPacket.
Software
Name
Versions affected
< 2.0.7
Fix
FreeRTOS/FreeRTOS-Plus-TCP@b95fdc3