Описание
[GHSA-4f8x-49pf-3x5v: Buffer overflow in APRS message construction]
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps-legacy/xenial | needs-triage | |
| esm-apps/bionic | needs-triage | |
| esm-apps/focal | needs-triage | |
| esm-apps/jammy | needs-triage | |
| esm-apps/noble | needs-triage | |
| esm-apps/resolute | needs-triage | |
| jammy | needs-triage | |
| noble | needs-triage | |
| resolute | needs-triage |
Показывать по
10
Связанные уязвимости
redhat
около 2 месяцев назад
A flaw was found in svxlink's LocationInfo/APRS functionality. The updateQsoStatus() function in AprsTcpClient.cpp formats a remote EchoLink station's callsign and info string into a fixed 80-byte stack buffer using sprintf without length checks. A remote attacker controlling an EchoLink station can supply a long callsign or info string to overflow the buffer, potentially enabling code execution.