Name
dlt-daemon
Version
2.18.8+2
Type
library
Description
Diagnostic Log and Trace
Licenses
MPL-2.0
PURL
-
CPE
cpe:2.3:*:*:dlt-daemon:2.18.8+2.18.9gitX:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
cmake: Link with libatomic on rv32/rv64
Khem Raj <raj.khem@gmail.com>
2
Don't execute processes as a specific user.
Andrei Gherzan <andrei.gherzan@windriver.com>
3
Fix handle returned value (#384)
Bui Nguyen Quoc Thanh <49302843+thanhbnq@users.noreply.github.com>
CVE-2022-39836
CVE-2022-39837
4
Modify systemd config directory
Andrei Gherzan <andrei.gherzan@windriver.com>
5
Fix memory leak
Le Van Khanh <Khanh.LeVan@vn.bosch.com>
CVE-2023-26257
6
Check for negative index in dlt_file_message
Michael Methner <mmethner@de.adit-jv.com>
CVE-2023-36321
Vulnerabilities#
Name
Analysis
Description
Patched
Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflow via the component /shared/dlt_common.c.
Patched
An issue was discovered in the Connected Vehicle Systems Alliance (COVESA; formerly GENIVI) dlt-daemon through 2.18.8. Dynamic memory is not released after it is allocated in dlt-control-common.c.
Patched
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a NULL pointer dereference,
Patched
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.