PT-2024-23303 · Fastdds+1 · Fastdds+1

Mirusu400

·

Published

2024-05-13

·

Updated

2024-05-18

·

CVE-2024-30259

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions FastDDS versions prior to 2.14.1 FastDDS versions prior to 2.13.5 FastDDS versions prior to 2.10.4 FastDDS versions prior to 2.6.8
Description FastDDS is a C++ implementation of the DDS standard of the OMG. When a publisher serves a malformed RTPS packet, a heap buffer overflow occurs on the subscriber, potentially leading to a DOS attack. This issue can remotely crash any Fast-DDS process.
Recommendations For versions prior to 2.14.1, update to version 2.14.1 or later. For versions prior to 2.13.5, update to version 2.13.5 or later. For versions prior to 2.10.4, update to version 2.10.4 or later. For versions prior to 2.6.8, update to version 2.6.8 or later.

Exploit

Fix

DoS

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-30259
GHSA-QCJ9-939P-P662

Affected Products

Debian
Fastdds