This thread has been locked.

If you have a related question, please click the "Ask a related question" button in the top right corner. The newly created question will be automatically linked to this question.

LAUNCHCC3220MODASF: TI-PSIRT-2022-090141: SimpleLink CC32XX SDK Integer Overflow Issues

Part Number: LAUNCHCC3220MODASF

Hello,

the PSIRT Notification mentions the following:

  • Integer overflow in HTTPClient_setHeaderByName
  • Integer overflow in StrMpl_getAllocStr

It states that this is valid for the SDK versions v6.10.00.05 and earlier.

The function HTTPClient_setHeaderByName is located in the source file source\ti\net\http\httpclient.c.
At least in the SDK versions 5_30_00_08, 6_10_00_05 and 7_10_00_13.this file is not changed..

The function StrMpl_getAllocStr is located in the file source\ti\net\utils\str_mpl.c.
That file is also not changed between the mentioned SDK version.

Is the mentioned overflow not fixed in the source file containing the function code?
Where are the two overflow fixed?

Where can I get detailed information about that overflows to evaluate  if I need to switch the used SDK version?

Many thanks in advance,
Roman Jordan