Stack-based buffer overflow in microjson and gpsd - CVE-2018-17937
Published: February 15, 2019
Vulnerability details
The vulnerability allows an adjacent attacker to gain elevated privileges on the target system.
The vulnerability exists due to a boundary error when handling malicious input. An adjacent attacker can trigger stack-based buffer overflow and execute arbitrary code via traffic on Port 2947/TCP or crafted JSON inputs.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
gpsd
Gentoo Linux
Fedora
gpsd
How to mitigate CVE-2018-17937
Update microjson to version 1.4.
gpsd - update to 3.18
gpsd - addressed in versions 3.17-6.fc28, 3.17-6.fc29