Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.
{
"binaries": [
{
"binary_name": "cyclonedds-dev",
"binary_version": "0.8.2-5"
},
{
"binary_name": "cyclonedds-tools",
"binary_version": "0.8.2-5"
},
{
"binary_name": "libcycloneddsidl0",
"binary_version": "0.8.2-5"
},
{
"binary_name": "libddsc0",
"binary_version": "0.8.2-5"
}
]
}
{
"binaries": [
{
"binary_name": "cyclonedds-dev",
"binary_version": "0.10.4-1.1build3"
},
{
"binary_name": "cyclonedds-tools",
"binary_version": "0.10.4-1.1build3"
},
{
"binary_name": "libcycloneddsidl0t64",
"binary_version": "0.10.4-1.1build3"
},
{
"binary_name": "libddsc0t64",
"binary_version": "0.10.4-1.1build3"
}
]
}
{
"binaries": [
{
"binary_name": "cyclonedds-dev",
"binary_version": "0.10.5-1"
},
{
"binary_name": "cyclonedds-tools",
"binary_version": "0.10.5-1"
},
{
"binary_name": "libcycloneddsidl0t64",
"binary_version": "0.10.5-1"
},
{
"binary_name": "libddsc0t64",
"binary_version": "0.10.5-1"
}
]
}