cve/2023/CVE-2023-39945.md
2024-06-18 02:51:15 +02:00

18 lines
922 B
Markdown

### [CVE-2023-39945](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39945)
![](https://img.shields.io/static/v1?label=Product&message=Fast-DDS&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20%3C%202.6.5%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-248%3A%20Uncaught%20Exception&color=brighgreen)
### Description
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5, a data submessage sent to PDP port raises unhandled `BadParamException` in fastcdr, which in turn crashes fastdds. Versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5 contain a patch for this issue.
### POC
#### Reference
- https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-2rq6-8j7x-frr9
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds