Description
eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow.
No analysis available yet.
Remediation
Vendor Solution
Update eCosCentric eCosPro RTOS to version 4.5.4 or newer – Update available
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-14171 | eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow. |
References
History
Wed, 16 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-04-16T16:25:33.142Z
Reserved: 2021-02-19T00:00:00.000Z
Link: CVE-2021-27417
Updated: 2024-08-03T20:48:17.190Z
Status : Modified
Published: 2022-05-03T21:15:08.180
Modified: 2024-11-21T05:57:56.823
Link: CVE-2021-27417
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD