Switch System Flaws: Difference between revisions

No edit summary
Line 1,030: Line 1,030:
This is called from nn::pia::session::MeshProtocol::ParseConnectionReport().
This is called from nn::pia::session::MeshProtocol::ParseConnectionReport().
| Heap buffer overflow triggered by a Pia MeshProtocol message sent to a host device.
| Heap buffer overflow triggered by a Pia MeshProtocol message sent to a host device.
| Fixed in v5.9.3, exact version unknown.
| v5.9.3
| v5.9.1/v5.9.3
| v5.9.1/v5.9.2/v5.9.3
| November 11, 2022
| November 11, 2022
| November 15, 2022
| November 15, 2022
Line 1,048: Line 1,048:
In fixed versions ReceivedFragmentData::Receive added a bunch of validation before the memcpy.
In fixed versions ReceivedFragmentData::Receive added a bunch of validation before the memcpy.
| Stack/heap buffer overflow triggered by a Pia LanProtocol message.
| Stack/heap buffer overflow triggered by a Pia LanProtocol message.
| Fixed in v5.9.3, exact version unknown.
| v5.9.3
| v5.9.1/v5.9.3
| v5.9.1/v5.9.2/v5.9.3
| November 14, 2022
| November 14, 2022
| November 15, 2022
| November 15, 2022
Line 1,061: Line 1,061:
In fixed versions the arraycount field is now validated.
In fixed versions the arraycount field is now validated.
| Stack buffer overflow triggered by a Pia SessionProtocol message.
| Stack buffer overflow triggered by a Pia SessionProtocol message.
| Fixed in v5.9.3, exact version unknown.
| v5.9.3
| v5.9.1/v5.9.3
| v5.9.1/v5.9.2/v5.9.3
| November 14, 2022
| November 14, 2022
| November 15, 2022
| November 15, 2022