PT-2021-10230 · Eclipse · Eclipse Iot Cyclone Dds Project
Luckyzflop
·
Published
2021-08-23
·
Updated
2021-08-30
·
CVE-2020-18735
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Eclipse IOT Cyclone DDS Project version 0.1.0
Description:
A heap buffer overflow in the /src/dds stream.c file causes the DDS subscriber server to crash.
Recommendations:
For Eclipse IOT Cyclone DDS Project version 0.1.0, consider disabling access to the /src/dds stream.c file as a temporary workaround until a patch is available. Restrict the use of the DDS subscriber server to minimize the risk of exploitation.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse Iot Cyclone Dds Project