Genivi

Diagnostic Log And Trace

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 25.10.2022 17:15:56
  • Zuletzt bearbeitet 07.05.2025 15:15:53

An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-b...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 25.10.2022 17:15:56
  • Zuletzt bearbeitet 07.05.2025 15:15:54

An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a NULL p...

  • EPSS 0.02%
  • Veröffentlicht 16.06.2022 16:15:09
  • Zuletzt bearbeitet 21.11.2024 07:04:17

An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.

  • EPSS 0.26%
  • Veröffentlicht 28.05.2021 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:01:16

GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing the special characters could cause a vulnerable component to crash. All the applications wh...

  • EPSS 1.33%
  • Veröffentlicht 10.02.2021 07:15:12
  • Zuletzt bearbeitet 21.11.2024 05:29:08

The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon (versions prior to 2.18.6).

Exploit
  • EPSS 0.6%
  • Veröffentlicht 30.11.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:23:59

A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon through 2.18.5 (GENIVI Diagnostic Log and Trace) allows arbitrary code execution because fscanf is misused (no limit on the number of characters to be read in the forma...