CVE-2019-13465: High severity ros vulnerability
An issue was discovered in the ROS communications-related packages (aka roscomm or ros-melodic-ros-comm) through 1.14.3. ROSASSERTMSG only works when ROSASSERTENABLED is defined. This leads to a problem in the remove() function in clients/roscpp/src/libros/spinner.cpp. When ROSASSERTENABLED is not defined, the iterator loop will run out of the scope of the array, and cause denial of service for other components (that depend on the communication-related functions of this package). NOTE: The reporter of this issue now believes it was a false alarm.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13465?
CVE-2019-13465 is an issue discovered in the ROS communications-related packages, specifically ros_comm or ros-melodic-ros-comm, through version 1.14.3.
How severe is CVE-2019-13465?
CVE-2019-13465 has a severity rating of 8.6, which is considered high.
What software is affected by CVE-2019-13465?
The ROS communications-related packages, specifically ros_comm or ros-melodic-ros-comm, up to and including version 1.14.3, are affected by CVE-2019-13465.
What is the issue in the remove() function in clients/roscpp/src/libros/spinner.cpp?
The issue in the remove() function in clients/roscpp/src/libros/spinner.cpp is related to the ROS_ASSERT_ENABLED not being defined, causing a problem in the function.
Where can I find more information about CVE-2019-13465?
More information about CVE-2019-13465 can be found at the following link: https://github.com/ros/ros_comm/issues/1748