漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Vanetza: Remote Denial of Service via Uncaught Exception in ASN.1/OER Parsing
Vulnerability Description
Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When processing malformed network packets containing corrupted ASN.1/OER structures (e.g., invalid length fields or malformed certificate encoding), the ASN.1 wrapper (asn1c_wrapper.cpp) raises a std::runtime_error. This exception is not caught at the parsing boundary and propagates to std::terminate, resulting in process termination. This vulnerability is fixed with commit 62dfe58a8342512b6e1947d75821402ada524f1a.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未捕获的异常
Vulnerability Title
Vanetza 安全漏洞
Vulnerability Description
Vanetza是Raphael Riebl个人开发者的一个车载通信协议套件的开源实现。 Vanetza 26.02及之前版本存在安全漏洞,该漏洞源于ASN.1/OER解析管道中处理畸形网络数据包时,ASN.1包装器抛出std::runtime_error异常未被捕获,传播至std::terminate导致进程终止。
CVSS Information
N/A
Vulnerability Type
N/A