PT-2026-102768 · Netx · Netx
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
A heap-buffer-overflow occurs when a TFTP server responds with a short ERROR packet. The client only verifies that the datagram is at least four bytes long, but fails to compare the
buffer ptr against the nx packet append ptr when copying the message string. If an ERROR packet lacks a terminating NUL byte, the loop continues reading past the end of the packet until a zero byte is encountered or the 64-byte destination buffer is filled. This allows adjacent packet pool memory to be leaked into the nx tftp client error string variable, which may then be displayed or logged by the application. This issue affects the nxd tftp client file read() function and other receive paths in the nxd tftp client.c file.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netx