PT-2026-84586 · Ion-Dtn · Ion-Dtn
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ION-DTN versions prior to 4.2.0
Description
An out-of-bounds read exists in the
decodeSdnv() function. Unauthenticated remote attackers can read memory by sending truncated SDNV (Self-Delimiting Numeric Value) values via a UDP datagram to the LTP link service input port. This action can trigger reads up to nine bytes beyond buffer boundaries and cause byte counters to underflow.Recommendations
Update to version 4.2.0 or later.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ion-Dtn