PT-2020-17157 · Genivia · Dlt-Daemon

Khanh Luong Hong Duy

·

Published

2020-11-30

·

Updated

2023-02-03

·

CVE-2020-29394

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dlt-daemon versions 2.8.5 through 2.18.5
Description A buffer overflow in the dlt filter load function in dlt common.c allows arbitrary code execution because fscanf is misused, with no limit on the number of characters to be read in the format argument.
Recommendations For versions 2.8.5 through 2.18.5, consider disabling the dlt filter load function until a patch is available to prevent potential arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29394
DLA-3231-1

Affected Products

Dlt-Daemon