cve/2023/CVE-2023-39948.md

18 lines
891 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-39948](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39948)
![](https://img.shields.io/static/v1?label=Product&message=Fast-DDS&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20%3C%202.6.5%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-248%3A%20Uncaught%20Exception&color=brighgreen)
### Description
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.5, the `BadParamException` thrown by Fast CDR is not caught in Fast DDS. This can remotely crash any Fast DDS process. Versions 2.10.0 and 2.6.5 contain a patch for this issue.
### POC
#### Reference
- https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-x9pj-vrgf-f68f
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds