The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon (versions prior to 2.18.6).
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/GENIVI/dlt-daemon/issues/265 | third party advisory |
https://github.com/GENIVI/dlt-daemon/compare/v2.18.5...v2.18.6 | third party advisory patch |
https://us-cert.cisa.gov/ics/advisories/icsa-21-147-01 | third party advisory us government resource |
https://lists.debian.org/debian-lts-announce/2022/12/msg00016.html | mailing list third party advisory patch |