Описание
[GHSA-x5r8-rq62-q9cj: remotetrx: unvalidated audio length + exposed transceiver control]
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| svxlink | fixed | 26.05.1-1 | package | |
| svxlink | no-dsa | trixie | package |
Примечания
https://github.com/sm0svx/svxlink/security/advisories/GHSA-x5r8-rq62-q9cj
Связанные уязвимости
ubuntu
16 дней назад
[GHSA-x5r8-rq62-q9cj: remotetrx: unvalidated audio length + exposed transceiver control]
redhat
около 2 месяцев назад
A flaw was found in svxlink's remotetrx NetUplink component. An unvalidated audio length field enables an out-of-bounds read, and when AUTH_KEY is not set, transceiver control functions are exposed to unauthenticated remote access. This allows unauthorized control of radio hardware connected to the svxlink system.