CVE-2018-20578 is a high-severity vulnerability affecting NuttX versions prior to 7.27, specifically within the netlib_parsehttpurl() function. This flaw allows a remote attacker to trigger an infinite loop in the webclient by crafting a malicious HTTP 3xx Location header with a URL exceeding the hostlen buffer. The attack requires no user interaction and can lead to a denial of service (availability impact). There is no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.27CPE matchmatch criteria | cpe:2.3:a:nuttx:nuttx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.