Required CVE Record Information
Description
A buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or a missing '\0' character.
References 5 Total
- https://github.com/RT-Thread/rt-thread/issues/8291
- https://github.com/hnsecurity/vulns/blob/main/HNS-2024-05-rt-thread.txt
- https://security.humanativaspa.it/multiple-vulnerabilities-in-rt-thread-rtos/
- https://seclists.org/fulldisclosure/2024/Mar/28
- openwall.com: [oss-security] 20240305 HNS-2024-05 - HN Security Advisory - Multiple vulnerabilities in RT-Thread RTOS mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 5 Total
- https://github.com/RT-Thread/rt-thread/issues/8291 x_transferred
- https://github.com/hnsecurity/vulns/blob/main/HNS-2024-05-rt-thread.txt x_transferred
- https://security.humanativaspa.it/multiple-vulnerabilities-in-rt-thread-rtos/ x_transferred
- https://seclists.org/fulldisclosure/2024/Mar/28 x_transferred
- openwall.com: [oss-security] 20240305 HNS-2024-05 - HN Security Advisory - Multiple vulnerabilities in RT-Thread RTOS mailing-listx_transferred