CVE Vulnerabilities

CVE-2021-37146

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Sep 28, 2021 | Modified: Oct 06, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 allows remote attackers to cause a Denial of Service in ros_comm via a crafted XMLRPC call.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Ros-comm Ros * 1.4.11 (including)
Ros-comm Ros 1.15.0 (including) 1.15.11 (including)
Ros-kinetic-ros-comm Ubuntu ros-esm/xenial *
Ros-melodic-ros-comm Ubuntu ros-esm/bionic *
Ros-ros-comm Ubuntu bionic *
Ros-ros-comm Ubuntu hirsute *
Ros-ros-comm Ubuntu impish *
Ros-ros-comm Ubuntu kinetic *
Ros-ros-comm Ubuntu lunar *
Ros-ros-comm Ubuntu mantic *
Ros-ros-comm Ubuntu trusty *
Ros-ros-comm Ubuntu xenial *

References