Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:42813
HistoryAug 16, 2023 - 6:59 a.m.

Buffer Overflow

2023-08-1606:59:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
buffer overflow
libzephyr
memcpy
usb_dc_native_posix.c
application crash
vulnerability
software

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

24.4%

libzephyr.so is vulnerable to Buffer Overflows. The vulnerability exists in the memcpy function at usb_dc_native_posix.c due to not properly handling the buffer size, which allows an attacker to cause an application crash.

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

24.4%

Related for VERACODE:42813