CVE-2023-39949
Summary
| CVE | CVE-2023-39949 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-11 14:15:00 UTC |
| Updated | 2023-08-21 18:17:00 UTC |
| Description | eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS process. Versions 2.9.1 and 2.6.5 contain a patch for this issue. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| github.com/eProsima/Fast-DDS/blob/v2.9.0/src/cpp/rtps/messages/MessageRe... |
MISC |
github.com |
|
| Improper validation of sequence numbers leading to remotely reachable assertion failure · Advisory · eProsima/Fast-DDS · GitHub |
MISC |
github.com |
|
| Debian -- Security Information -- DSA-5481-1 fastdds |
MISC |
www.debian.org |
|
| Assertion failure in SequenceNumber.h via malformed SPDP packet only when compiled in logging-enabled (Debug) mode · Issue #3236 · eProsima/Fast-DDS · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 6000204 Debian Security Update for fastdds (DSA 5481-1)