Covesa Dlt-Daemon vulnerabilities

8 known vulnerabilities affecting covesa/dlt-daemon.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-36321HIGHCVSS 7.5≤ 2.18.82023-10-17
CVE-2023-36321 [HIGH] CWE-120 CVE-2023-36321: Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflo Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflow via the component /shared/dlt_common.c.
nvdosv
CVE-2023-26257HIGHCVSS 7.5≤ 2.18.82023-02-27
CVE-2023-26257 [HIGH] CWE-401 CVE-2023-26257: An issue was discovered in the Connected Vehicle Systems Alliance (COVESA; formerly GENIVI) dlt-daem An issue was discovered in the Connected Vehicle Systems Alliance (COVESA; formerly GENIVI) dlt-daemon through 2.18.8. Dynamic memory is not released after it is allocated in dlt-control-common.c.
nvdosv
CVE-2022-39837MEDIUMCVSS 5.5≥ 0, < 2.18.9-12022-10-25
CVE-2022-39837 [MEDIUM] CVE-2022-39837: An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2 An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a NULL pointer dereference,
osv
CVE-2022-39836MEDIUMCVSS 5.5≥ 0, < 2.18.9-12022-10-25
CVE-2022-39836 [MEDIUM] CVE-2022-39836: An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2 An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.
osv
CVE-2022-31291HIGHCVSS 7.5≥ 0, < 2.18.6-1+deb11u1≥ 0, < 2.18.6-2.12022-06-16
CVE-2022-31291 [HIGH] CVE-2022-31291: An issue in dlt_config_file_parser An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.
osv
CVE-2021-29507MEDIUMCVSS 6.5≥ 0, < 2.18.8-12021-05-28
CVE-2021-29507 [MEDIUM] CVE-2021-29507: GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing the special characters could cause a vulnerable component to crash. All the applications which are using the configuration file could fail to generate their dlt logs in system. As of time of publication, no patch exists. As a wo
osv
CVE-2020-36244CRITICALCVSS 9.8≥ 0, < 2.18.6-12021-02-10
CVE-2020-36244 [CRITICAL] CVE-2020-36244: The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute ar The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon (versions prior to 2.18.6).
osv
CVE-2020-29394HIGHCVSS 7.8≥ 0, < 2.18.5-0.32020-11-30
CVE-2020-29394 [HIGH] CVE-2020-29394: A buffer overflow in the dlt_filter_load function in dlt_common A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon through 2.18.5 (GENIVI Diagnostic Log and Trace) allows arbitrary code execution because fscanf is misused (no limit on the number of characters to be read in the format argument).
osv