PT-2021-4110 · Genivia+1 · Genivi Diagnostic Log/Trace+1
Thanhbnq
·
Published
2021-03-30
·
Updated
2022-08-02
·
CVE-2021-29507
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GENIVI Diagnostic Log and Trace (DLT) versions 2.10.0 through 2.18.6
Description
The issue is related to the incorrect handling of special characters in configuration files, which can cause a vulnerable component to crash. This can lead to applications using the configuration file failing to generate their logs. The problem can be exploited by a remote attacker to cause a denial of service. As of the time of publication, no patch exists for this issue.
Recommendations
For GENIVI DLT versions 2.10.0 through 2.18.6, as a temporary workaround, one may manually check the integrity of the information in the configuration file to prevent the crash of the vulnerable component.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Genivi Diagnostic Log/Trace