Null Pointer Dereference in coap_client_exchange_blockwise2
function in Keith Cullen FreeCoAP 1.0 allows remote attackers to cause a denial of service and potentially execute arbitrary code via a specially crafted CoAP packet that causes coap_msg_get_payload(resp)
to return a null pointer, which is then dereferenced in a call to memcpy
.
The product dereferences a pointer that it expects to be valid but is NULL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freecoap | Keith-cullen | 1.0 (including) | 1.0 (including) |