{"id":"CVE-2020-17468","details":"An issue was discovered in FNET through 4.6.4. The code for processing the hop-by-hop header (in the IPv6 extension headers) doesn't check for a valid length of an extension header, and therefore an out-of-bounds read can occur in _fnet_ip6_ext_header_handler_options in fnet_ip6.c, leading to Denial-of-Service.","modified":"2026-07-08T20:30:35.895390Z","published":"2020-12-11T23:15:13.620Z","references":[{"type":"ADVISORY","url":"http://fnet.sourceforge.net/manual/fnet_history.html"},{"type":"ADVISORY","url":"https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01"},{"type":"ADVISORY","url":"https://www.kb.cert.org/vuls/id/815128"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/butok/fnet","events":[{"introduced":"0"},{"last_affected":"fdfcc63a5715b524ab1809fa67e9b939b5510325"}],"database_specific":{"cpe":"cpe:2.3:a:butok:fnet:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"4.6.4"}],"source":"CPE_RANGE"}}],"versions":["v4.6.4","v4.6.3","v4.6.2","v4.6.1","v4.6.0","v4.5.3","v4.5.2","v4.5.1","v4.5.0","v4.4.1","v4.4.0","v4.3.0","v4.2.0","v4.1.1","v4.1.0","v4.0.2","v4.0.1","v4.0.0","v3.9.4","v3.9.3updated","v3.9.3prev","v3.9.3pre","v3.9.3","v3.9.2","v3.9.1","v3.9.0","v3.8.2","v3.8.1","v3.8.0","v3.7.0","v3.6.1","3.6.0","v3.5.0","v3.4.0","FNET_3.3.0","v3.2.0","3.1.1","v3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-17468.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}