Vulnerability Description
Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by ffconfigFREE, which (by default) is a macro definition of vPortFree(), but it is reused to flush modified file content from the cache to disk by the function FF_FlushCache().
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amazon | Freertos\+Fat | 160919a |
Related Weaknesses (CWE)
References
- https://sourceforge.net/p/freertos/bugs/199/ExploitThird Party Advisory
- https://sourceforge.net/p/freertos/bugs/199/ExploitThird Party Advisory
FAQ
What is CVE-2019-18178?
CVE-2019-18178 is a vulnerability with a CVSS score of 7.5 (HIGH). Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by ffconfigFREE, which (by default) is a macro definiti...
How severe is CVE-2019-18178?
CVE-2019-18178 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18178?
Check the references section above for vendor advisories and patch information. Affected products include: Amazon Freertos\+Fat.