The `news` MonkeyC operation code in CIQ API version 1.0...
Critical severity
Unreviewed
Published
May 23, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
May 23, 2023
Published to the GitHub Advisory Database
May 23, 2023
Last updated
Apr 4, 2024
The
news
MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends past its end. Upon loading the string, the GarminOS TVM component may read out-of-bounds memory.References