VendorsGENIVIdiagnostic_log_and_traceall versions
Vulnerabilities

GENIVI Diagnostic Log and Trace

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-36244
The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon (versions prior to 2.18.6).
Published 2021-02-10 · Modified
9.8EPSS 0.042
CVE-2020-29394
A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon through 2.18.5 (GENIVI Diagnostic Log and Trace) allows arbitrary code execution because fscanf is misused (no limit on the number of characters to be read in the format argument).
Published 2020-11-30 · Modified
7.8EPSS 0.019
CVE-2022-31291
An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.
Published 2022-06-16 · Modified
7.5EPSS 0.010
CVE-2021-29507
dlt-daemon could crash if there is special character in dlt.conf
Published 2021-05-28 · Modified
6.5EPSS 0.007
CVE-2022-39836
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.
Published 2022-10-24 · Modified
5.5EPSS 0.004
CVE-2022-39837
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a NULL pointer dereference,
Published 2022-10-24 · Modified
5.5EPSS 0.004