CVE-2022-39836
- EPSS 0.03%
- Veröffentlicht 25.10.2022 17:15:56
- Zuletzt bearbeitet 07.05.2025 15:15:53
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-b...
CVE-2022-39837
- EPSS 0.03%
- Veröffentlicht 25.10.2022 17:15:56
- Zuletzt bearbeitet 07.05.2025 15:15:54
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a NULL p...
CVE-2022-31291
- EPSS 0.02%
- Veröffentlicht 16.06.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 07:04:17
An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.
CVE-2021-29507
- EPSS 0.26%
- Veröffentlicht 28.05.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:16
GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing the special characters could cause a vulnerable component to crash. All the applications wh...
CVE-2020-36244
- EPSS 1.33%
- Veröffentlicht 10.02.2021 07:15:12
- Zuletzt bearbeitet 21.11.2024 05:29:08
The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon (versions prior to 2.18.6).
CVE-2020-29394
- EPSS 0.6%
- Veröffentlicht 30.11.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:23:59
A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon through 2.18.5 (GENIVI Diagnostic Log and Trace) allows arbitrary code execution because fscanf is misused (no limit on the number of characters to be read in the forma...