CVE-2021-42147
Published Jan 24, 2024
·Updated
Buffer over-read vulnerability in the dtls_sha256_update function in Contiki-NG tinyDTLS through master branch 53a0d97 allows remote attackers to cause a denial of service via crafted data packet.
Affected Software
1 affected component
Contiki-NG tinyDTLS=2018-08-30
Event History
Jan 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-42147?
CVE-2021-42147 is a denial of service vulnerability that can impact the availability of affected systems.
2
How do I fix CVE-2021-42147?
To mitigate CVE-2021-42147, update to the latest version of Contiki-NG tinyDTLS that addresses this buffer over-read issue.
3
Which versions of Contiki-NG tinyDTLS are affected by CVE-2021-42147?
CVE-2021-42147 affects the 2018-08-30 version of Contiki-NG tinyDTLS on the master branch.
4
Can CVE-2021-42147 be exploited remotely?
Yes, CVE-2021-42147 can be exploited by remote attackers through crafted data packets.
5
What impact does CVE-2021-42147 have on applications?
CVE-2021-42147 can cause a denial of service, potentially crashing applications using the affected library.