Files
meta-openembedded/meta-oe/recipes-extended
Yogita Urade 92a5b3ebf0 dlt-daemon: fix CVE-2022-39836 and CVE-2022-39837
CVE-2022-39836:
An issue was discovered in Connected Vehicle Systems Alliance (COVESA)
dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted
DLT file that crashes the process can be created. This is due to missing
validation checks. There is a heap-based buffer over-read of one byte.

CVE-2022-39837:
An issue was discovered in Connected Vehicle Systems Alliance (COVESA)
dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted
DLT file that crashes the process can be created. This is due to missing
validation checks. There is a NULL pointer dereference.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2022-39836
https://nvd.nist.gov/vuln/detail/CVE-2022-39837

Upstream patch:
https://github.com/COVESA/dlt-daemon/commit/855e0017a980d2990c16f7dbf3b4983b48fac272

Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2025-03-06 09:43:54 -05:00
..
2022-04-11 08:52:55 -07:00
2023-04-04 09:04:45 -04:00
2022-04-19 09:45:38 -07:00
2022-04-11 07:46:51 -07:00
2022-05-03 06:49:08 -07:00
2023-09-06 09:13:26 -04:00
2024-12-08 15:01:32 -05:00
2023-03-22 07:32:56 -04:00
2023-08-25 10:39:56 -04:00
2023-07-25 07:23:15 -04:00
2022-04-12 09:28:25 -07:00
2022-01-12 09:35:18 -08:00
2021-08-03 10:21:25 -07:00
2022-04-14 19:42:10 -07:00
2022-03-26 18:15:11 -07:00
2022-10-04 15:46:54 -04:00
2025-02-09 07:55:22 -08:00
2022-03-24 09:45:25 -07:00
2022-07-21 07:36:05 -07:00
2022-05-17 05:57:10 -07:00
2022-07-21 07:17:15 -07:00
2022-07-21 07:17:15 -07:00
2022-03-24 09:45:25 -07:00
2021-08-03 10:21:25 -07:00
2022-01-12 09:35:18 -08:00
2021-08-03 10:21:25 -07:00