PT-2026-85285 · Unknown · Essential-Moos
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MOOS essential-moos versions prior to 10.0.2
Description
A buffer overflow exists in the
CMOOSUDPLink::ReadPktFromArray() function. Remote attackers can corrupt heap memory by sending crafted UDP datagrams with negative declared lengths to the configured UDPListen port. This triggers an oversized memcpy operation that writes beyond the destination buffer, resulting in heap corruption and denial of service.Recommendations
Update MOOS essential-moos to version 10.0.2 or later.
Fix
DoS
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Essential-Moos