CVE-2019-5038: Buffer Overflow
An exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a stack-based buffer overflow, resulting in code execution. An attacker can trigger this vulnerability by convincing the user to open a specially crafted Weave command.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5038?
CVE-2019-5038 is an exploitable command execution vulnerability in the print-tlv command of Weave tool.
How does CVE-2019-5038 work?
CVE-2019-5038 can be triggered by a specially crafted weave TLV, causing a stack-based buffer overflow and leading to code execution.
Which software is affected by CVE-2019-5038?
Openweave Openweave-core version 4.0.2 is affected by CVE-2019-5038.
What is the severity of CVE-2019-5038?
CVE-2019-5038 has a severity rating of 8.8 (high).
How can CVE-2019-5038 be fixed?
To fix CVE-2019-5038, users should update to a version of Openweave Openweave-core that is not affected by the vulnerability.