libcoap 4.3.1 contains a buffer over-read via the function coap_parse_oscore_conf_mem at coap_oscore.c.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/obgm/libcoap/issues/1117 | third party advisory issue tracking exploit |
https://github.com/obgm/libcoap/pull/1118 | patch |
https://github.com/obgm/libcoap/tags | product |