Описание
Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| cyclonedds | fixed | 0.8.1-2 | package | |
| cyclonedds | no-dsa | bullseye | package |
Примечания
No mention of CVE upstream
https://projects.eclipse.org/projects/iot.cyclonedds
https://www.cisa.gov/uscert/ics/advisories/icsa-21-315-02
EPSS
Связанные уязвимости
Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.
Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.
Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.
EPSS