Описание
[GHSA-4f8x-49pf-3x5v: Buffer overflow in APRS message construction]
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| svxlink | fixed | 26.05.1-1 | package | |
| svxlink | no-dsa | trixie | package |
Примечания
https://github.com/sm0svx/svxlink/security/advisories/GHSA-4f8x-49pf-3x5v
Связанные уязвимости
ubuntu
16 дней назад
[GHSA-4f8x-49pf-3x5v: Buffer overflow in APRS message construction]
redhat
около 2 месяцев назад
A flaw was found in svxlink's LocationInfo/APRS functionality. The updateQsoStatus() function in AprsTcpClient.cpp formats a remote EchoLink station's callsign and info string into a fixed 80-byte stack buffer using sprintf without length checks. A remote attacker controlling an EchoLink station can supply a long callsign or info string to overflow the buffer, potentially enabling code execution.