UBUNTU-CVE-2013-2038

Source
https://ubuntu.com/security/CVE-2013-2038
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-2038.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2013-2038
Upstream
Related
  • USN-1820-1
Withdrawn
2025-07-18T16:42:51Z
Published
2013-05-02T00:00:00Z
Modified
2026-02-04T02:29:11.539213Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

The NMEA0183 driver in gpsd before 3.9 allows remote attackers to cause a denial of service (daemon termination) and possibly execute arbitrary code via a GPS packet with a malformed $GPGGA interpreted sentence that lacks certain fields and a terminator. NOTE: a separate issue in the AIS driver was also reported, but it might not be a vulnerability.

References

Affected packages

Ubuntu:14.04:LTS / gpsd

Package

Name
gpsd
Purl
pkg:deb/ubuntu/gpsd@3.9-3?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9-3

Affected versions

3.*
3.9-2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "gpsd",
            "binary_version": "3.9-3"
        },
        {
            "binary_name": "gpsd-clients",
            "binary_version": "3.9-3"
        },
        {
            "binary_name": "gpsd-dbg",
            "binary_version": "3.9-3"
        },
        {
            "binary_name": "libgps-dev",
            "binary_version": "3.9-3"
        },
        {
            "binary_name": "libgps20",
            "binary_version": "3.9-3"
        },
        {
            "binary_name": "libqgpsmm-dev",
            "binary_version": "3.9-3"
        },
        {
            "binary_name": "libqgpsmm20",
            "binary_version": "3.9-3"
        },
        {
            "binary_name": "python-gps",
            "binary_version": "3.9-3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-2038.json"