PT-2020-17157 · Genivia · Dlt-Daemon
Khanh Luong Hong Duy
·
Published
2020-11-30
·
Updated
2023-02-03
·
CVE-2020-29394
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
dlt-daemon versions 2.8.5 through 2.18.5
Description
A buffer overflow in the
dlt filter load function in dlt common.c allows arbitrary code execution because fscanf is misused, with no limit on the number of characters to be read in the format argument.Recommendations
For versions 2.8.5 through 2.18.5, consider disabling the
dlt filter load function until a patch is available to prevent potential arbitrary code execution.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dlt-Daemon