The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon (versions prior to 2.18.6).
References
| Link | Resource |
|---|---|
| https://github.com/GENIVI/dlt-daemon/compare/v2.18.5...v2.18.6 | Patch Third Party Advisory |
| https://github.com/GENIVI/dlt-daemon/issues/265 | Third Party Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-21-147-01 | Third Party Advisory US Government Resource |
Configurations
Information
Published : 2021-02-10 07:15
Updated : 2021-06-02 15:17
NVD link : CVE-2020-36244
Mitre link : CVE-2020-36244
JSON object : View
Products Affected
genivi
- diagnostic_log_and_trace
CWE
CWE-787
Out-of-bounds Write
