cve/2023/CVE-2023-39947.md

18 lines
994 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-39947](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39947)
![](https://img.shields.io/static/v1?label=Product&message=Fast-DDS&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20%3C%202.6.6%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-122%3A%20Heap-based%20Buffer%20Overflow&color=brighgreen)
### Description
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, even after the fix at commit 3492270, malformed `PID_PROPERTY_LIST` parameters cause heap overflow at a different program counter. This can remotely crash any Fast-DDS process. Versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6 contain a patch for this issue.
### POC
#### Reference
- https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-mf55-5747-c4pv
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds