CVE-2021-29507
published 2021-05-28CVE-2021-29507: GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.75%
51.2th percentile
GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing the special characters could cause a vulnerable component to crash. All the applications which are using the configuration file could fail to generate their dlt logs in system. As of time of publication, no patch exists. As a workaround, one may check the integrity of information in configuration file manually.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| covesa | dlt-daemon | >= 0 < 2.18.8-1 | 2.18.8-1 |
| covesa | dlt-daemon | >= 0 < 2.18.8-1 | 2.18.8-1 |
| covesa | dlt-daemon | >= 0 < 2.18.8-1 | 2.18.8-1 |
| debian | dlt-daemon | < dlt-daemon 2.18.8-1 (bookworm) | dlt-daemon 2.18.8-1 (bookworm) |
| genivi | diagnostic_log_and_trace | 2.10.0 – 2.18.6 | — |
| genivi | dlt-daemon | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian5.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-29507: dlt-daemon - GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In ver...
vendor_debian·2021·CVSS 5.7
CVE-2021-29507 [MEDIUM] CVE-2021-29507: dlt-daemon - GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In ver...
GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing the special characters could cause a vulnerable component to crash. All the applications which are using the configuration file could fail to generate their dlt logs in system. As of time of publication, no patch exists. As a workaround, one may check the integrity of information in configuration file manually.
Scope: local
bookworm: resolved (fixed in 2.18.8-1)
bullseye: open
forky: resolved (fixed in 2.18.8-1)
sid: resolved (fixed in 2.18.8-1)
trixie: resolved (fixed in 2.18.8-1)
OSV
CVE-2021-29507: GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface
osv·2021-05-28·CVSS 6.5
CVE-2021-29507 [MEDIUM] CVE-2021-29507: GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface
GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing the special characters could cause a vulnerable component to crash. All the applications which are using the configuration file could fail to generate their dlt logs in system. As of time of publication, no patch exists. As a workaround, one may check the integrity of information in configuration file manually.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-28
Published