Beschreibung
INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f, contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to crash the daemon by sending malformed XML with mismatched tags whose names exceed 1024 bytes. Attackers can send a single TCP packet on port 7624 with mismatched XML tags to trigger an unbounded sprintf() write into a fixed 1024-byte stack buffer in MsgQueue.cpp, terminating the daemon and disrupting all active client and driver sessions.
CVSS 7.5EPSS 0.482%Risiko 0.78
Quelle öffnen- Veröffentlicht
- 2026-08-17 18:18:12
- Betroffene Versionen
- <=2.2.4.2
- Typ
- Sonstiges
- Zuletzt geändert
- 2026-08-17 20:16:46
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H