CVE-2023-39949
published 2023-08-11CVE-2023-39949: eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.89%
55.4th percentile
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS process. Versions 2.9.1 and 2.6.5 contain a patch for this issue.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | fastdds | < fastdds 2.9.1+ds-1+deb12u1 (bookworm) | fastdds 2.9.1+ds-1+deb12u1 (bookworm) |
| eprosima | fast-dds | < 2.6.5 | 2.6.5 |
| eprosima | fast-dds | — | — |
| eprosima | fast_dds | — | — |
| eprosima | fast_dds | >= 2.6.0 < 2.6.5 | 2.6.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv9.1CRITICAL
vendor_debian7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
fastdds vulnerabilities
osv·2023-08-24·CVSS 9.1
CVE-2021-38425 [CRITICAL] fastdds vulnerabilities
fastdds vulnerabilities
It was discovered that Fast DDS incorrectly handled certain inputs.
A remote attacker could possibly use this issue to cause a denial of
service and information exposure. This issue only affected Ubuntu
22.04 LTS. (CVE-2021-38425)
It was discovered that Fast DDS incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash.
(CVE-2023-39534, CVE-2023-39945, CVE-2023-39946, CVE-2023-39947,
CVE-2023-39948, CVE-2023-39949)
OSV
CVE-2023-39949: eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group
osv·2023-08-11·CVSS 7.5
CVE-2023-39949 [HIGH] CVE-2023-39949: eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS process. Versions 2.9.1 and 2.6.5 contain a patch for this issue.
Ubuntu
Fast DDS vulnerabilities
vendor_ubuntu·2023-08-24·CVSS 7.5
CVE-2023-39534 [HIGH] Fast DDS vulnerabilities
Title: Fast DDS vulnerabilities
Summary: Fast DDS could be made to crash or expose sensitive information if it
received specially crafted input.
It was discovered that Fast DDS incorrectly handled certain inputs.
A remote attacker could possibly use this issue to cause a denial of
service and information exposure. This issue only affected Ubuntu
22.04 LTS. (CVE-2021-38425)
It was discovered that Fast DDS incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash.
(CVE-2023-39534, CVE-2023-39945, CVE-2023-39946, CVE-2023-39947,
CVE-2023-39948, CVE-2023-39949)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2023-39949: fastdds - eprosima Fast DDS is a C++ implementation of the Data Distribution Service stand...
vendor_debian·2023·CVSS 7.5
CVE-2023-39949 [HIGH] CVE-2023-39949: fastdds - eprosima Fast DDS is a C++ implementation of the Data Distribution Service stand...
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS process. Versions 2.9.1 and 2.6.5 contain a patch for this issue.
Scope: local
bookworm: resolved (fixed in 2.9.1+ds-1+deb12u1)
bullseye: resolved (fixed in 2.1.0+ds-9+deb11u1)
forky: resolved (fixed in 2.10.1+ds-2)
sid: resolved (fixed in 2.10.1+ds-2)
trixie: resolved (fixed in 2.10.1+ds-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/eProsima/Fast-DDS/blob/v2.9.0/src/cpp/rtps/messages/MessageReceiver.cpp#L1059https://github.com/eProsima/Fast-DDS/issues/3236https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-3jv9-j9x3-95cghttps://www.debian.org/security/2023/dsa-5481https://github.com/eProsima/Fast-DDS/blob/v2.9.0/src/cpp/rtps/messages/MessageReceiver.cpp#L1059https://github.com/eProsima/Fast-DDS/issues/3236https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-3jv9-j9x3-95cghttps://www.debian.org/security/2023/dsa-5481
2023-08-11
Published