Wind River Systems VxWorks缓冲区溢出漏洞


基本信息

时间: 2019-08-02

风险等级: 高

CNVD: CNVD-2019-25699

原地址: https://www.cnvd.org.cn/flaw/show/CNVD-2019-25699


描述
WindRiverSystemsVxWorks是美国风河系统(WindRiverSystems)公司的一套嵌入式实时操作系统(RTOS)。WindRiverSystemsVxWorks7版本和6.9版本中对IPv4数据包IP选项的解析存在缓冲区溢出漏洞。攻击者可利用该漏洞借助带有无效选项的IPv4数据包造成tNet0任务崩溃,执行代码。
产品
WindRiverSystemsWindRiverSystemsVxWorks6.9WindRiverSystemsWindRiverSystemsVxWorks6.8WindRiverSystemsWindRiverSystemsVxWorks6.7WindRiverSystemsWindRiverSystemsVxWorks6.6
解决方案
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
CVE
CVE-2019-12256
补丁
Wind River Systems VxWorks缓冲区溢出漏洞的补丁
来源
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/security-advisory-ipnet/security-advisory-ipnet.pdf https://www.tenable.com/blog/critical-vulnerabilities-dubbed-urgent11-place-devices-running-vxworks-at-risk-of-rce-attacks https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12256