CVE Vulnerabilities

CVE-2023-39948

Uncaught Exception

Published: Aug 11, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.5, the BadParamException thrown by Fast CDR is not caught in Fast DDS. This can remotely crash any Fast DDS process. Versions 2.10.0 and 2.6.5 contain a patch for this issue.

Weakness

An exception is thrown from a function, but it is not caught.

Affected Software

Name Vendor Start Version End Version
Fast_dds Eprosima 2.6.0 (including) 2.6.5 (excluding)
Fast_dds Eprosima 2.10.0-rc1 (including) 2.10.0-rc1 (including)
Fastdds Ubuntu esm-apps/jammy *
Fastdds Ubuntu jammy *
Fastdds Ubuntu lunar *
Fastdds Ubuntu upstream *

References