PT-2021-10230 · Eclipse · Eclipse Iot Cyclone Dds Project

Luckyzflop

·

Published

2021-08-23

·

Updated

2021-08-30

·

CVE-2020-18735

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Eclipse IOT Cyclone DDS Project version 0.1.0
Description: A heap buffer overflow in the /src/dds stream.c file causes the DDS subscriber server to crash.
Recommendations: For Eclipse IOT Cyclone DDS Project version 0.1.0, consider disabling access to the /src/dds stream.c file as a temporary workaround until a patch is available. Restrict the use of the DDS subscriber server to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-18735

Affected Products

Eclipse Iot Cyclone Dds Project