Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-27213: Ethernut Download

An issue was discovered in Ethernut Nut/OS 5.1. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of current and future TCP connections and either hijack existing ones or spoof future ones. While the ISN generator seems to adhere to RFC 793 (where a global 32-bit counter is incremented roughly every 4 microseconds), proper ISN generation should aim to follow at least the specifications outlined in RFC 6528.

CVE
#mac#windows#linux#debian#apache#git#c++

Nut/OS Downloads

Stable Version 5.1

ethernut-5.1.0-1.exe
Executable installation for Windows PCs.

ethernut-5.1.0-1.tar.gz
Source code package for Linux and OS X. More details are available here.

Latest Beta Version

ethernut-5.2.4.exe
Executable installation for Windows PCs.

ethernut-5.2.4.tar.gz
Source code package for Linux and OS X. More details are available here.

Code Repository

The cutting edge development version is available in an Apache Subversion repository at ethernut.svn.sourceforge.net.

If you like to work locally with Git on the Subversion repository, get the bare repository at ethernut-code.git.tar.gz.
Unpack the tar file with

tar fxz ethernut-code.git.tar.gz

change to the Ethernut code directory with

cd ethernut-code

and checkout the files

git checkout – .

You can stay up to date with

git svn rebase

Previous Releases

Versions, which are no longer maintained, can be downloaded from the archive.

Note! Binary code created from version 5.0.4 beta for Cortex-M may contain code with the following license:

Copyright © 2005-2009 Luminary Micro, Inc. All rights reserved. Software License Agreement

Luminary Micro, Inc. (LMI) is supplying this software for use solely and exclusively on LMI’s microcontroller products.

The software is owned by LMI and/or its suppliers, and is protected under applicable copyright laws. All rights are reserved. You may not combine this software with “viral” open-source software in order to form a larger program. Any use in violation of the foregoing restrictions may subject the user to criminal sanctions under applicable laws, as well as to civil liability for the breach of the terms and conditions of this license.

We have removed this version.

Toolchains****AVR 8-Bit Cross Development****Debian Packages

packages.debian.org
Debian official packages.

Windows Installer

WinAVR
is a complete Win32 installation package, which contains the AVR-GCC compiler and many additional tools.

AVR32 Cross Development

AVR32 GNU Toolchain
Atmel offers free development environments for PCs running Linux and Windows.

ARM Cross Development****Debian Packages

GNU binary utilities for arm-elf cross development
This package is a collection of utilities required for the assembly, linking, symbol dumping, object dumping, object copying and other operations for position independent code on ARM targets using the ELF file format.

GNU C compiler for arm-elf cross development
GNU C cross compiler for ARM targets using the ELF file format.

GNU debugger for arm-elf cross development
GNU debugger, configured for remote debugging of ARM targets using the ELF file format.

Standard C library for arm-elf cross development
This C library intended for use on ARM targets using the ELF file format. Newlib is a conglomeration of several library parts, all under free software licenses that make them easily usable on embedded products.

Windows and Mac OS X

YAGARTO
is the recommended toolchain for 32-bit ARM targets.

Ethernut 5 Specific

en5flasher-20130719.zip
Automagic Flasher for Ethernut 5, described on this page. This release of the Linux kernel 3.8.8 additionally contains the binary images of SAMBoot and U-Boot-2013.01.01.

ethernut5-image-20130604.zip
Ethernut 5 root file system image for Linux 3.8.8, built with Yocto 1.4.

meta-egnite-20130531.tar.bz2
build-ethernut5-3.8-20130531.tar.bz2
Files needed to build Yocto for Ethernut 5.

en5pwrman-20110610.zip
Power management firmware for Ethernut 5, mentioned at the end of this page.

Previous Releases

en5flasher-20120308.zip
Automagic Flasher für Ethernut 5, described on this page. This first release of the Linux kernel 3.2.9 additionally contains the binary images of SAMBoot and U-Boot-2011.03.

console-image-ethernut5-20120308.zip
First release of the Ethernut 5 Linux root file system image for kernel 3.2.9. Should be installed in conjunction with en5flasher-20120308.zip.

en5flasher-20120305.zip
Automagic Flasher für Ethernut 5, described on this page. This second release for Linux 2.6.37 contains the binary images of SAMBoot, U-Boot-2011.03 and Linux kernel. The latter now supports USB memory sticks and cameras, PPP over UMTS/GPRS, GPS mice and more. The kernel now runs with data cache enabled.

console-image-ethernut5-20120305.zip
Second release of the Ethernut 5 Linux root file system image. Should be installed in conjunction with en5flasher-20120305.zip.

egnite-oe-overlay-r2.tar.bz2
egnite-oe-build-2.6.37-r2.tar.bz2
OpenEmbedded overlays to build U-Boot, Linux and a root filesystem for Ethernut 5.

en5flasher-20110610.zip
Automagic flasher for Ethernut 5, described this page.

console-image-ethernut5-20110525.zip
Ethernut 5 Linux root file system image. Use this first version with en5flasher-20110610.zip.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907