Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-1000660

TOCK version prior to commit 42f7f36e74088036068d62253e1d8fb26605feed. For example dfde28196cd12071fcf6669f7654be7df482b85d contains a Insecure Permissions vulnerability in Function get_package_name in the file kernel/src/tbfheader.rs, variable "pub package_name: &'static str," in the file process.rs that can result in A tock capsule (untrusted driver) could access arbitrary memory by using only safe code. This vulnerability appears to have been fixed in commit 42f7f36e74088036068d62253e1d8fb26605feed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2018-1000660
  • Tockos » Tock » Version: 1.0
    cpe:2.3:o:tockos:tock:1.0
  • Tockos » Tock » Version: 1.1
    cpe:2.3:o:tockos:tock:1.1


Contact Us

Shodan ® - All rights reserved