7.8
CVSSv3

CVE-2020-29394

Published: 30/11/2020 Updated: 03/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon up to and including 2.18.5 (GENIVI Diagnostic Log and Trace) allows arbitrary code execution because fscanf is misused (no limit on the number of characters to be read in the format argument).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

genivi diagnostic log and trace

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #976228 dlt-daemon: CVE-2020-29394 Package: src:dlt-daemon; Maintainer for src:dlt-daemon is Aigars Mahinovs <aigarius@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 1 Dec 2020 20:39:02 UTC Severity: grave Tags: security, upstream Found in versions dlt-daemon/ ...