A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_request_put_block function in src/coap_block.c.

Project Subscriptions

Vendors Products
Libcoap Subscribe
Libcoap Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 10 Oct 2024 13:30:00 +0000

Type Values Removed Values Added
Description A Buffer Overflow vulnerability in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_request_put_block function in src/coap_block.c. A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_request_put_block function in src/coap_block.c.

Wed, 09 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Libcoap
Libcoap libcoap
Weaknesses CWE-120
CPEs cpe:2.3:a:libcoap:libcoap:*:*:*:*:*:*:*:*
Vendors & Products Libcoap
Libcoap libcoap
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Oct 2024 16:00:00 +0000

Type Values Removed Values Added
Description A Buffer Overflow vulnerability in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_request_put_block function in src/coap_block.c.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-10T13:03:25.204364

Reserved: 2024-09-11T00:00:00

Link: CVE-2024-46304

cve-icon Vulnrichment

Updated: 2024-10-09T16:43:04.027Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-09T16:15:04.437

Modified: 2024-10-10T14:15:05.100

Link: CVE-2024-46304

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses