First published: Tue Aug 20 2019(Updated: )
An exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a stack-based buffer overflow, resulting in code execution. An attacker can trigger this vulnerability by convincing the user to open a specially crafted Weave command.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Openweave Openweave-core | =4.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5038 is an exploitable command execution vulnerability in the print-tlv command of Weave tool.
CVE-2019-5038 can be triggered by a specially crafted weave TLV, causing a stack-based buffer overflow and leading to code execution.
Openweave Openweave-core version 4.0.2 is affected by CVE-2019-5038.
CVE-2019-5038 has a severity rating of 8.8 (high).
To fix CVE-2019-5038, users should update to a version of Openweave Openweave-core that is not affected by the vulnerability.