Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-43628
HistoryDec 05, 2023 - 12:00 a.m.

CVE-2023-43628

2023-12-0500:00:00
ubuntu.com
ubuntu.com
11
vulnerability
integer underflow
gpsd
ntrip stream parsing
memory corruption
network packets
attack vector

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

13.2%

An integer underflow vulnerability exists in the NTRIP Stream Parsing
functionality of GPSd 3.25.1~dev. A specially crafted network packet can
lead to memory corruption. An attacker can send a malicious packet to
trigger this vulnerability.

Notes

Author Note
mdeslaur vulnerable code introduced here: https://gitlab.com/gpsd/gpsd/-/commit/6ccd477f5e21a45f6c52a21ad323c93e59aa2461 https://gitlab.com/gpsd/gpsd/-/commit/c1c1c2706c4f5b9bf3be437d0a8f0106ef00c5e7

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

13.2%