CVE-2020-29394: Buffer Overflow
A buffer overflow in the dltfilterload function in dltcommon.c from dlt-daemon through 2.18.5 (GENIVI Diagnostic Log and Trace) allows arbitrary code execution because fscanf is misused (no limit on the number of characters to be read in the format argument).
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-29394?
CVE-2020-29394 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2020-29394?
To mitigate CVE-2020-29394, upgrade to the latest version of dlt-daemon that resolves the buffer overflow issue.
What software is affected by CVE-2020-29394?
CVE-2020-29394 affects dlt-daemon versions up to and including 2.18.5, as well as Debian Linux 10.0.
What kind of attack does CVE-2020-29394 enable?
CVE-2020-29394 allows attackers to exploit a buffer overflow to execute arbitrary code remotely.
Is CVE-2020-29394 exploitable without authentication?
Yes, CVE-2020-29394 can be exploited remotely without requiring authentication, making it particularly dangerous.