CVE Vulnerabilities

CVE-2021-38443

Improper Handling of Syntactically Invalid Structure

Published: May 05, 2022 | Modified: May 13, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.

Weakness

The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification.

Affected Software

Name Vendor Start Version End Version
Cyclonedds Eclipse * 0.8.0 (excluding)
Cyclonedds Ubuntu impish *
Cyclonedds Ubuntu kinetic *
Cyclonedds Ubuntu lunar *
Cyclonedds Ubuntu mantic *

References