7.5
CVSSv3

CVE-2023-43628

Published: 05/12/2023 Updated: 11/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacker can send a malicious packet to trigger this vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

gpsd project gpsd 3.25.1

Vendor Advisories

Debian Bug report logs - #1057667 gpsd: CVE-2023-43628 Package: src:gpsd; Maintainer for src:gpsd is Boian Bonev <bbonev@ipacctcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 6 Dec 2023 22:00:02 UTC Severity: important Tags: security, upstream Found in version gpsd/325-2 Reply or subsc ...
Description<!---->An integer overflow vulnerability was found in gpsd A specially crafted network packet can lead to integer overflow and memory corruptionAn integer overflow vulnerability was found in gpsd A specially crafted network packet can lead to integer overflow and memory corruption ...