Описание
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-apps/focal | needed | |
| esm-apps/jammy | needed | |
| esm-apps/noble | not-affected | |
| focal | ignored | end of standard support, was needed |
| jammy | needed | |
| mantic | not-affected | 2.18.10-5 |
| noble | not-affected | |
| oracular | not-affected | |
| plucky | not-affected |
Показывать по
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) ...
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.
EPSS
5.5 Medium
CVSS3