CVE-2024-6444

No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.
Configurations

Configuration 1 (hide)

cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:*

History

13 Nov 2024, 15:24

Type Values Removed Values Added
References () https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-qj4r-chj6-h7qp - () https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-qj4r-chj6-h7qp - Vendor Advisory
CVSS v2 : unknown
v3 : 6.3
v2 : unknown
v3 : 6.5
First Time Zephyrproject zephyr
Zephyrproject
CPE cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:*
CWE CWE-787

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) No hay una validación adecuada de la longitud de la entrada del usuario en olcp_ind_handler en zephyr/subsys/bluetooth/services/ots/ots_client.c.

04 Oct 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-04 07:15

Updated : 2024-11-13 15:24


NVD link : CVE-2024-6444

Mitre link : CVE-2024-6444

CVE.ORG link : CVE-2024-6444


JSON object : View

Products Affected

zephyrproject

  • zephyr
CWE
CWE-787

Out-of-bounds Write

CWE-122

Heap-based Buffer Overflow