Description
A stack-based buffer overflow was discovered in the xtimor NMEA library (aka nmealib) 0.5.3. nmea_parse() in parser.c allows an attacker to trigger denial of service (even arbitrary code execution in a certain context) in a product using this library via malformed data.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-8949 | A stack-based buffer overflow was discovered in the xtimor NMEA library (aka nmealib) 0.5.3. nmea_parse() in parser.c allows an attacker to trigger denial of service (even arbitrary code execution in a certain context) in a product using this library via malformed data. |
References
| Link | Providers |
|---|---|
| https://www.cnblogs.com/tr3e/p/9662324.html |
|
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:39:59.706Z
Reserved: 2018-09-18T00:00:00.000Z
Link: CVE-2018-17174
No data.
Status : Modified
Published: 2018-09-21T17:29:07.483
Modified: 2024-11-21T03:54:00.570
Link: CVE-2018-17174
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD