Integer Underflow Vulnerability in GPSd by GPSD Developers
CVE-2023-43628

5.9MEDIUM

Key Information:

Vendor

Gpsd

Status
Vendor
CVE Published:
5 December 2023

What is CVE-2023-43628?

An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. This flaw could allow attackers to exploit specially crafted network packets, potentially leading to memory corruption. By sending such packets, an attacker may manipulate the system's behavior, raising serious security concerns for users and systems relying on GPSd for precise geographical data processing.

Affected Version(s)

GPSd 3.25.1~dev

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Dimitrios Tatsis of Cisco Talos.
.