PT-2010-2310 · Geo++ · Geo++ Gncaster
Published
2010-02-04
·
Updated
2018-10-10
·
CVE-2010-0553
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Geo++ GNCASTER versions 1.4.0.7 and earlier
Description
The issue allows remote authenticated users to cause a denial of service, potentially leading to an application crash, and may also enable the execution of arbitrary code. This can be achieved by sending a long NMEA data sentence.
Recommendations
For Geo++ GNCASTER versions 1.4.0.7 and earlier, consider updating to a newer version that contains a fix for this issue, although the specific fixed version is not provided in the available data. As a temporary workaround, restrict access to the NMEA data sentence processing functionality to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geo++ Gncaster