The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon (versions prior to 2.18.6).
References
Link | Resource |
---|---|
https://github.com/GENIVI/dlt-daemon/compare/v2.18.5...v2.18.6 | Patch Third Party Advisory |
https://github.com/GENIVI/dlt-daemon/issues/265 | Third Party Advisory |
https://us-cert.cisa.gov/ics/advisories/icsa-21-147-01 | Third Party Advisory US Government Resource |
https://lists.debian.org/debian-lts-announce/2022/12/msg00016.html | Patch Third Party Advisory |
Information
Published : 2021-02-09 23:15
Updated : 2023-02-03 11:12
NVD link : CVE-2020-36244
Mitre link : CVE-2020-36244
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
debian
- debian_linux
genivi
- diagnostic_log_and_trace