In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leading to heap buffer overflow. This can cause an application crash or on some platforms even the execution of remote code. If your application is used in open networks or there are untrusted nodes in the network it is highly recommend to apply the patch. This was patched with commit 033ab5b. Users of version 1.4.x should upgrade to version 1.4.3 when available. As a workaround changes of commit 033ab5b can be applied to older versions.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2020-08-26T18:00:16
Updated: 2024-08-04T13:08:22.296Z
Reserved: 2020-06-25T00:00:00
Link: CVE-2020-15158
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-08-26T18:15:10.287
Modified: 2024-11-21T05:04:58.113
Link: CVE-2020-15158
Redhat
No data.