CVE Vulnerabilities

CVE-2023-39945

Uncaught Exception

Published: Aug 11, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5, a data submessage sent to PDP port raises unhandled BadParamException in fastcdr, which in turn crashes fastdds. Versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5 contain a patch for this issue.

Weakness

An exception is thrown from a function, but it is not caught.

Affected Software

NameVendorStart VersionEnd Version
Fast_ddsEprosima2.6.0 (including)2.6.5 (excluding)
Fast_ddsEprosima2.9.0 (including)2.9.2 (excluding)
Fast_ddsEprosima2.10.0 (including)2.10.2 (excluding)
FastddsUbuntuesm-apps/jammy*
FastddsUbuntujammy*
FastddsUbuntulunar*
FastddsUbuntuupstream*

References