Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-42459

Опубликовано: 16 окт. 2023
Источник: nvd
CVSS3: 8.6
CVSS3: 7.5
EPSS Низкий

Описание

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). In affected versions specific DATA submessages can be sent to a discovery locator which may trigger a free error. This can remotely crash any Fast-DDS process. The call to free() could potentially leave the pointer in the attackers control which could lead to a double free. This issue has been addressed in versions 2.12.0, 2.11.3, 2.10.3, and 2.6.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*
Версия до 2.6.7 (исключая)
cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*
Версия от 2.10.0 (включая) до 2.10.3 (исключая)
cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*
Версия от 2.11.0 (включая) до 2.11.1 (включая)

EPSS

Процентиль: 52%
0.00288
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-415
CWE-415

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 2 лет назад

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). In affected versions specific DATA submessages can be sent to a discovery locator which may trigger a free error. This can remotely crash any Fast-DDS process. The call to free() could potentially leave the pointer in the attackers control which could lead to a double free. This issue has been addressed in versions 2.12.0, 2.11.3, 2.10.3, and 2.6.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.6
debian
больше 2 лет назад

Fast DDS is a C++ implementation of the DDS (Data Distribution Service ...

CVSS3: 8.6
fstec
больше 2 лет назад

Уязвимость библиотеки Fast DDS, связанная с использованием памяти после её освобождения, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 52%
0.00288
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-415
CWE-415