PT-2021-11978 · Genivia · Genivi Diagnostic Log/Trace

Published

2021-02-10

·

Updated

2023-02-03

·

CVE-2020-36244

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: GENIVI Diagnostic Log and Trace (DLT) versions prior to 2.18.6
Description: The daemon in GENIVI Diagnostic Log and Trace (DLT) is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon. The issue is specifically related to the dlt buffer write block function in shared/dlt common.c.
Recommendations: For versions prior to 2.18.6, update to version 2.18.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the DLT-Daemon to minimize the risk of exploitation.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36244
DLA-3231-1

Affected Products

Genivi Diagnostic Log/Trace