Versioni gpsd 2.90 a 3.17 e microjson versioni 1,0 a 1,3, un progetto open source, permettono un overflow stack-based buffer, che può consentire attaccanti remoti di eseguire codice arbitrario su piattaforme embedded tramite traffico sulla porta 2947 / TCP o artigianale ingressi JSON. |
http://www.securityfocus.com/bid/107029 https://security.gentoo.org/glsa/202009-17 https://ics-cert.us-cert.gov/advisories/ICSA-18-310-01 https://lists.debian.org/debian-lts-announce/2019/03/msg00040.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17937 |
Vulnerabilità: CVE-2018-17937
