Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-43628

Опубликовано: 05 дек. 2023
Источник: redhat
CVSS3: 7.5

Описание

An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacker can send a malicious packet to trigger this vulnerability.

An integer overflow vulnerability was found in gpsd. A specially crafted network packet can lead to an integer overflow and cause memory corruption.

Отчет

The identified flaw is absent in all versions of the gpsd release currently shipped by Red Hat.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9gpsd-minimalNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-191

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 2 лет назад

An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacker can send a malicious packet to trigger this vulnerability.

CVSS3: 5.9
nvd
около 2 лет назад

An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacker can send a malicious packet to trigger this vulnerability.

CVSS3: 5.9
debian
около 2 лет назад

An integer underflow vulnerability exists in the NTRIP Stream Parsing ...

CVSS3: 5.9
github
около 2 лет назад

An integer overflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacker can send a malicious packet to trigger this vulnerability.

7.5 High

CVSS3