Write-what-where Condition
CVE-2021-38441
Summary
Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser.
- LOW
- LOCAL
- LOW
- UNCHANGED
- NONE
- LOW
- LOW
- HIGH
CWE-123 - Write-what-where Condition
Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.
References
Advisory Timeline
- Published