CVE-2019-13445: Integer Overflow
Published Dec 30, 2019
·Updated
An issue was discovered in the ROS communications-related packages (aka roscomm or ros-melodic-ros-comm) through 1.14.3. parseOptions() in tools/rosbag/src/record.cpp has an integer overflow when a crafted split option can be entered on the command line.
Affected Software
1 affected component
ros ros-comm<=1.14.3
Remediation
Patch Available
Event History
Dec 30, 2019
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-13445.
2
What is the severity of CVE-2019-13445?
The severity of CVE-2019-13445 is critical with a score of 9.8.
3
What is the affected software for CVE-2019-13445?
The affected software for CVE-2019-13445 is Ros Ros-comm version up to and including 1.14.3.
4
What is the CWE ID for CVE-2019-13445?
The CWE ID for CVE-2019-13445 is 190.
5
How can I fix CVE-2019-13445?
To fix CVE-2019-13445, you should update to a version of ros_comm that is not affected by the vulnerability.