Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
RTKLIB 2.4.3 - Out-of-bounds Write in decode_type1033 via Crafted RTCM3 Message
Vulnerability Description
RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buffer size, allowing up to 191-byte overflow into fixed 64-byte descriptor fields. An attacker controlling an NTRIP or serial RTCM3 correction stream can craft a valid CRC-bearing type-1033 message to corrupt adjacent rtcm_t object members, potentially achieving arbitrary code execution or denial of service.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
跨界内存写
Vulnerability Title
Tomoji Takasu RTKLIB 缓冲区错误漏洞
Vulnerability Description
Tomoji Takasu RTKLIB是日本Tomoji Takasu个人开发者的一个全球导航卫星系统标准与精确定位算法软件包。 Tomoji Takasu RTKLIB 2.4.3及之前版本存在缓冲区错误漏洞,该漏洞源于decode_type1033函数未将长度计数器限制为目标缓冲区大小,导致越界写入,可能造成任意代码执行或拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A