CVE-2020-17441
An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 headers does not validate whether the IPv6 payload length field is equal to the actual size of the payload, which leads to an Out-of-Bounds read during the ICMPv6 checksum calculation, resulting in either Denial-of-Service or Information Disclosure. This affects picoipv6extensionheaders and picochecksumadder (in picoipv6.c and pico_frame.c).
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
, https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01, https://www.kb.cert.org/vuls/id/815128
