An issue was discovered in HCC Embedded InterNiche...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Aug 17, 2023
Description
Published by the National Vulnerability Database
Aug 19, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Aug 17, 2023
An issue was discovered in HCC Embedded InterNiche NicheStack through 4.3. The tfshnd():tftpsrv.c TFTP packet processing function doesn't ensure that a filename is adequately '\0' terminated; therefore, a subsequent call to strlen for the filename might read out of bounds of the protocol packet buffer (if no '\0' byte exists within a reasonable range).
References