Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-20578
HistoryDec 28, 2018 - 6:29 p.m.

Design/Logic Flaw

2018-12-2818:29:00
PRIOn knowledge base
www.prio-n.com
2

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.9%

An issue was discovered in NuttX before 7.27. The function netlib_parsehttpurl() in apps/netutils/netlib/netlib_parsehttpurl.c mishandles URLs longer than hostlen bytes (in the webclient, this is set by default to 40), leading to an Infinite Loop. The attack vector is the Location header of an HTTP 3xx response.

CPENameOperatorVersion
nuttxlt7.27

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.9%

Related for PRION:CVE-2018-20578