Vulnerabilities > CVE-2019-12101 - NULL Pointer Dereference vulnerability in Libnyoci Project Libnyoci 0.07.00

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
libnyoci-project
CWE-476

Summary

coap_decode_option in coap.c in LibNyoci 0.07.00rc1 mishandles certain packets with "Uri-Path: (null)" and consequently allows remote attackers to cause a denial of service (segmentation fault).

Vulnerable Configurations

Part Description Count
Application
Libnyoci_Project
1

Common Weakness Enumeration (CWE)