FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves a malformed `RTPS` packet, the subscriber crashes when creating `pthread`. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8 contain a patch for the issue.
References
Configurations
Configuration 1 (hide)
|
History
27 Jan 2025, 18:19
Type | Values Removed | Values Added |
---|---|---|
First Time |
Eprosima fast Dds
Eprosima |
|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:eprosima:fast_dds:2.14.0:*:*:*:*:*:*:* cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:* |
|
References | () https://drive.google.com/file/d/19W5UC52hPnAqVq_boZWO45d1TJ4WoCSh/view?usp=sharing - Exploit | |
References | () https://github.com/eProsima/Fast-DDS/commit/65236f93e9c4ea3ff9a49fba4dfd9e43eb94037b - Patch | |
References | () https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-53xw-465j-rxfh - Exploit, Vendor Advisory |
21 Nov 2024, 09:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://drive.google.com/file/d/19W5UC52hPnAqVq_boZWO45d1TJ4WoCSh/view?usp=sharing - | |
References | () https://github.com/eProsima/Fast-DDS/commit/65236f93e9c4ea3ff9a49fba4dfd9e43eb94037b - | |
References | () https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-53xw-465j-rxfh - | |
Summary |
|
14 May 2024, 15:22
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-14 15:22
Updated : 2025-01-27 18:19
NVD link : CVE-2024-30258
Mitre link : CVE-2024-30258
CVE.ORG link : CVE-2024-30258
JSON object : View
Products Affected
eprosima
- fast_dds
CWE