PT-2026-58008 · Debian+2 · Open62541
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
open62541 versions prior to 1.5.6
Description
A remote issue exists in the Shared Client Library within the
responseReadNamespacesArray() function located in the src/client/ua client connect.c file. Manipulation of the Server NamespaceArray argument can lead to a null pointer dereference, which occurs when a program attempts to read or write to a memory address that is null, typically resulting in a crash.Recommendations
Update to a version newer than 1.5.5.
As a temporary workaround, restrict the use of the
responseReadNamespacesArray() function to minimize the risk of exploitation.Exploit
Fix
Improper Resource Release
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open62541