When RPC is enabled in Wind River VxWorks 6.9 prior to 6.9.1, a specially crafted RPC request can trigger an integer overflow leading to an out-of-bounds memory copy. It may allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code.
References
Link | Resource |
---|---|
https://support2.windriver.com/index.php?page=security-notices | Vendor Advisory |
https://www.windriver.com/feeds/wind_river_security_notices.xml | Vendor Advisory |
https://support2.windriver.com/index.php?page=security-notices | Vendor Advisory |
https://www.windriver.com/feeds/wind_river_security_notices.xml | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://support2.windriver.com/index.php?page=security-notices - Vendor Advisory | |
References | () https://www.windriver.com/feeds/wind_river_security_notices.xml - Vendor Advisory |
Information
Published : 2019-05-29 17:29
Updated : 2024-11-21 04:52
NVD link : CVE-2019-9865
Mitre link : CVE-2019-9865
CVE.ORG link : CVE-2019-9865
JSON object : View
Products Affected
windriver
- vxworks
CWE
CWE-190
Integer Overflow or Wraparound