4.3
CVSSv2

CVE-2013-2038

Published: 06/02/2014 Updated: 07/02/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The NMEA0183 driver in gpsd prior to 3.9 allows remote malicious users to cause a denial of service (daemon termination) and possibly execute arbitrary code via a GPS packet with a malformed $GPGGA interpreted sentence that lacks certain fields and a terminator. NOTE: a separate issue in the AIS driver was also reported, but it might not be a vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 12.04

gpsd project gpsd 3.7

gpsd project gpsd 3.5

gpsd project gpsd 3.1

gpsd project gpsd 3.2

gpsd project gpsd 3.4

gpsd project gpsd 3.6

gpsd project gpsd

gpsd project gpsd 3.3

gpsd project gpsd 3.0

Vendor Advisories

Debian Bug report logs - #706665 gpsd: CVE-2013-2038 Package: src:gpsd; Maintainer for src:gpsd is Bernd Zeimetz <bzed@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 3 May 2013 04:45:02 UTC Severity: important Tags: patch, security Found in version gpsd/36-1 Fixed in versions gpsd/3 ...
gpsd could be made to crash or possibly run programs if it received specially crafted input ...