CVE-2022-39836
published 2022-10-25CVE-2022-39836: An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that…
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.42%
34.2th percentile
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| covesa | dlt-daemon | >= 0 < 2.18.9-1 | 2.18.9-1 |
| covesa | dlt-daemon | >= 0 < 2.18.9-1 | 2.18.9-1 |
| debian | dlt-daemon | < dlt-daemon 2.18.9-1 (forky) | dlt-daemon 2.18.9-1 (forky) |
| genivi | diagnostic_log_and_trace | <= 2.18.8 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-39836: dlt-daemon - An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemo...
vendor_debian·2022·CVSS 5.5
CVE-2022-39836 [MEDIUM] CVE-2022-39836: dlt-daemon - An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemo...
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.18.9-1)
sid: resolved (fixed in 2.18.9-1)
trixie: resolved (fixed in 2.18.9-1)
OSV
CVE-2022-39836: An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2
osv·2022-10-25·CVSS 5.5
CVE-2022-39836 [MEDIUM] CVE-2022-39836: An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.
GHSA
GHSA-8gjv-jwgc-cx6r: An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2
ghsa_unreviewed·2022-10-25
CVE-2022-39836 [MEDIUM] CWE-125 GHSA-8gjv-jwgc-cx6r: An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2024/06/msg00021.htmlhttps://sec-consult.com/vulnerability-lab/advisory/multiple-memory-corruption-vulnerabilities-in-covesa-dlt-daemon/https://seclists.org/fulldisclosure/2022/Sep/24https://lists.debian.org/debian-lts-announce/2024/06/msg00021.htmlhttps://sec-consult.com/vulnerability-lab/advisory/multiple-memory-corruption-vulnerabilities-in-covesa-dlt-daemon/https://seclists.org/fulldisclosure/2022/Sep/24
2022-10-25
Published