nhrp_packet_extension() in nhrp_packet.c:290-316 indexes two fixed-size 10-element arrays with extension & 0x7fff (range 0-32767) with no bounds check.
Triggered during unmarshall_packet() before authentication, causes crash or infinite CPU loop.
Description
Description
Details
Details
- Version
- -
- Is it a breaking change?
- Unspecified (possibly destroys the router)
- Issue type
- Security vulnerability