Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.
The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cyclonedds | Eclipse | * | 0.8.0 (excluding) |
Cyclonedds | Ubuntu | impish | * |
Cyclonedds | Ubuntu | kinetic | * |
Cyclonedds | Ubuntu | lunar | * |
Cyclonedds | Ubuntu | mantic | * |