CVE-2021-29507
dlt-daemon could crash if there is special character in dlt.conf
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing the special characters could cause a vulnerable component to crash. All the applications which are using the configuration file could fail to generate their dlt logs in system. As of time of publication, no patch exists. As a workaround, one may check the integrity of information in configuration file manually.
GENIVI Diagnostic Log and Trace (DLT) proporciona una interfaz de registro y seguimiento. En las versiones de GENIVI DLT comprendidas entre la versión 2.10.0 y la versión 2.18.6, un archivo de configuración que contenga los caracteres especiales podría provocar el fallo de un componente vulnerable. Todas las aplicaciones que utilizan el archivo de configuración podrían no generar sus registros dlt en el sistema. En el momento de la publicación, no existe ningún parche. Como solución, se puede comprobar manualmente la integridad de la información en el archivo de configuración
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-30 CVE Reserved
- 2021-05-28 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/GENIVI/dlt-daemon/security/advisories/GHSA-7cqp-2hqj-mh3f | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Genivi Search vendor "Genivi" | Diagnostic Log And Trace Search vendor "Genivi" for product "Diagnostic Log And Trace" | >= 2.10.0 <= 2.18.6 Search vendor "Genivi" for product "Diagnostic Log And Trace" and version " >= 2.10.0 <= 2.18.6" | - |
Affected
|