CVE-2020-36244

The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon (versions prior to 2.18.6).
References
Link Resource
https://github.com/GENIVI/dlt-daemon/compare/v2.18.5...v2.18.6 Patch Third Party Advisory
https://github.com/GENIVI/dlt-daemon/issues/265 Third Party Advisory
https://us-cert.cisa.gov/ics/advisories/icsa-21-147-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:genivi:diagnostic_log_and_trace:*:*:*:*:*:*:*:*

Information

Published : 2021-02-10 07:15

Updated : 2021-06-02 15:17


NVD link : CVE-2020-36244

Mitre link : CVE-2020-36244


JSON object : View

Products Affected

genivi

  • diagnostic_log_and_trace
CWE
CWE-787

Out-of-bounds Write