Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser.
{ "binaries": [ { "binary_name": "cyclonedds-tools", "binary_version": "0.8.2-5" }, { "binary_name": "libcycloneddsidl0", "binary_version": "0.8.2-5" }, { "binary_name": "libddsc0", "binary_version": "0.8.2-5" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-38441.json"
{ "binaries": [ { "binary_name": "cyclonedds-tools", "binary_version": "0.10.4-1.1build3" }, { "binary_name": "libcycloneddsidl0t64", "binary_version": "0.10.4-1.1build3" }, { "binary_name": "libddsc0t64", "binary_version": "0.10.4-1.1build3" } ] }
{ "binaries": [ { "binary_name": "cyclonedds-tools", "binary_version": "0.10.5-1" }, { "binary_name": "libcycloneddsidl0t64", "binary_version": "0.10.5-1" }, { "binary_name": "libddsc0t64", "binary_version": "0.10.5-1" } ] }
{ "binaries": [ { "binary_name": "cyclonedds-tools", "binary_version": "0.10.5-1build1" }, { "binary_name": "libcycloneddsidl0t64", "binary_version": "0.10.5-1build1" }, { "binary_name": "libddsc0t64", "binary_version": "0.10.5-1build1" } ] }