Vulnerability Details CVE-2020-24339
An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The DNS domain name record decompression functionality in pico_dns_decompress_name() in pico_dns_common.c does not validate the compression pointer offset values with respect to the actual data present in a DNS response packet, causing out-of-bounds reads that lead to Denial-of-Service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-24339
-
cpe:2.3:a:altran:picotcp-ng:-
-
cpe:2.3:a:altran:picotcp-ng:1.7.0
-
cpe:2.3:a:altran:picotcp:1.0
-
cpe:2.3:a:altran:picotcp:1.1
-
cpe:2.3:a:altran:picotcp:1.2
-
cpe:2.3:a:altran:picotcp:1.2.1
-
cpe:2.3:a:altran:picotcp:1.2.2
-
cpe:2.3:a:altran:picotcp:1.2.3
-
cpe:2.3:a:altran:picotcp:1.2.4
-
cpe:2.3:a:altran:picotcp:1.3.0
-
cpe:2.3:a:altran:picotcp:1.4.0
-
cpe:2.3:a:altran:picotcp:1.4.2
-
cpe:2.3:a:altran:picotcp:1.5.0
-
cpe:2.3:a:altran:picotcp:1.5.1
-
cpe:2.3:a:altran:picotcp:1.6.0
-
cpe:2.3:a:altran:picotcp:1.6.1
-
cpe:2.3:a:altran:picotcp:1.6.2
-
cpe:2.3:a:altran:picotcp:1.7.0