CVE-2025-34458 UNKNOWN
← Quay lại danh sách
Dịch vụ / phần mềm liên quan:
Chưa phân loại — không khớp danh sách dịch vụ/phần mềm đang theo dõi (xem/thêm ở
internal/cve/categories.go), hoặc NVD chưa cung cấp đủ dữ liệu vendor/sản phẩm cho CVE này.
⚠️ NVD chưa công bố điểm CVSS cho CVE này (thường do CVE vừa công bố, đang chờ NVD phân tích) — mức độ sẽ tự cập nhật ở lần đồng bộ sau.
Mô tả
wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the APRS MIC-E decoder function aprs_mic_e() located in src/decode_aprs.c. When processing a specially crafted AX.25 frame containing a MIC-E message with an empty or truncated comment field, the application triggers an unhandled assertion checking for a non-empty comment. This assertion failure causes immediate process termination, allowing a remote, unauthenticated attacker to cause a denial of service by sending malformed APRS traffic.
Chi tiết
| Trạng thái | Deferred |
| Điểm CVSS | 0.0 (v) |
| Vector CVSS | |
| Ngày công bố | 05:16 23/12/2025 |
| Ngày cập nhật | 17:10 28/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.
Tài liệu tham khảo
- [disclosure@vulncheck.com] https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-010-direwolf-stack-buffer-overflow-kiss-frame.md
- [disclosure@vulncheck.com] https://github.com/wb2osz/direwolf/commit/3658a87
- [disclosure@vulncheck.com] https://github.com/wb2osz/direwolf/issues/618
- [disclosure@vulncheck.com] https://www.vulncheck.com/advisories/wb2osz-direwolf-reachable-assertion-dos
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 17:17 28/09/2026 | CREATED | cve | UNKNOWN |