CVE-2020-29394 describes a buffer overflow vulnerability in the dlt_filter_load function of dlt-daemon versions up to 2.18.5, affecting Debian and GENIVI Diagnostic Log and Trace products. This flaw, stemming from the misuse of fscanf, allows for arbitrary code execution. Rated 7.8 HIGH on the CVSS scale, it requires user interaction and local access (AV:L/UI:R) but can lead to complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.18.5CPE matchmatch criteria | cpe:2.3:a:genivi:diagnostic_log_and_trace:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.