eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS process. Versions 2.9.1 and 2.6.5 contain a patch for this issue.
References
Link | Resource |
---|---|
https://github.com/eProsima/Fast-DDS/blob/v2.9.0/src/cpp/rtps/messages/MessageReceiver.cpp#L1059 | Third Party Advisory |
https://github.com/eProsima/Fast-DDS/issues/3236 | Third Party Advisory |
https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-3jv9-j9x3-95cg | Third Party Advisory |
https://www.debian.org/security/2023/dsa-5481 | Third Party Advisory |
Configurations
History
21 Aug 2023, 18:17
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-3jv9-j9x3-95cg - Third Party Advisory | |
References | (MISC) https://github.com/eProsima/Fast-DDS/issues/3236 - Third Party Advisory | |
References | (MISC) https://github.com/eProsima/Fast-DDS/blob/v2.9.0/src/cpp/rtps/messages/MessageReceiver.cpp#L1059 - Third Party Advisory | |
References | (MISC) https://www.debian.org/security/2023/dsa-5481 - Third Party Advisory | |
CPE | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:a:eprosima:fast_dds:2.9.0:*:*:*:*:*:*:* cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
21 Aug 2023, 04:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
11 Aug 2023, 15:18
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-11 14:15
Updated : 2024-02-05 00:01
NVD link : CVE-2023-39949
Mitre link : CVE-2023-39949
CVE.ORG link : CVE-2023-39949
JSON object : View
Products Affected
eprosima
- fast_dds
debian
- debian_linux
CWE
CWE-617
Reachable Assertion