Heap-based Buffer Overflow in CCN-lite 2.0.1: Memory Management Issue in mkAddToRelayCacheRequest

Heap-based Buffer Overflow in CCN-lite 2.0.1: Memory Management Issue in mkAddToRelayCacheRequest

CVE-2018-12889 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

An issue was discovered in CCN-lite 2.0.1. There is a heap-based buffer overflow in mkAddToRelayCacheRequest and in ccnl_populate_cache for an array lacking '\0' termination when reading a binary CCNx or NDN file. This can result in Heap Corruption. This was addressed by fixing the memory management in mkAddToRelayCacheRequest in ccn-lite-ctrl.c.

Learn more about our Web Application Penetration Testing UK.