A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.
2024-02-20T15:15:08.020
2025-02-12T18:51:08.283
Analyzed
CVSSv3.1: 8.7 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | weston-embedded | uc-tcp-ip | 3.06.01 | Yes |