Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflow via the component /shared/dlt_common.c.
[
{
"id": "CVE-2023-36321-21df466c",
"source": "https://github.com/michael-methner/dlt-daemon/commit/8ac9a080bee25e67e49bd138d81c992ce7b6d899",
"signature_version": "v1",
"target": {
"function": "dlt_file_message",
"file": "src/shared/dlt_common.c"
},
"deprecated": false,
"digest": {
"length": 784.0,
"function_hash": "42500842691663743478045165169024432787"
},
"signature_type": "Function"
},
{
"id": "CVE-2023-36321-89b55625",
"source": "https://github.com/michael-methner/dlt-daemon/commit/8ac9a080bee25e67e49bd138d81c992ce7b6d899",
"signature_version": "v1",
"target": {
"file": "src/shared/dlt_common.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"179869172186416439580683262602663212709",
"95763039670857813098731119545271756043",
"251870743626053504911774860114950243341",
"280814995539743560572916483962200121314"
],
"threshold": 0.9
},
"signature_type": "Line"
}
]