A remote attacker could send a specially-crafted request to an affected application, which could cause it to crash.
A heap-based buffer overflow was found in libmodbus in function modbus_reply() in src/modbus.c. A remote attacker could send a specially-crafted request to an affected application, which could cause it to crash. libmodbus was updated to version 1.0.2.
An information leak was found in libmodbus in the function modbus_get_reply_data(). A remote attacker could send a specially-crafted request to an affected application, which could cause it to crash.
An information leak was found in libmodbus in the function modbus_get_reply_data(). A remote attacker could send a specially-crafted request to an affected application, which could cause it to crash. libmodbus was updated to version 1.0.2. An information leak was found in libmodbus in the function modbus_get_reply_data(). A remote attacker could send a specially-crafted request to an affected application, which could cause it to crash. An information leak was found in libmodbus in the function modbus_get_reply_data(). A remote attacker could send a specially-crafted request to an affected application, which could cause it to crash. An information leak was found in libmodbus in the function modbus_get_reply_data(). A remote attacker could
Vulnerable packages: libmodbus-1.0.1-5
libmodbus-dev-1.0.2-5
Timeline
Published on: 08/29/2022 15:15:00 UTC
Last modified on: 09/05/2022 00:15:00 UTC
References
- https://github.com/stephane/libmodbus/issues/614
- https://bugzilla.redhat.com/show_bug.cgi?id=2045571
- https://github.com/stephane/libmodbus/commit/b4ef4c17d618eba0adccc4c7d9e9a1ef809fc9b6
- https://lists.debian.org/debian-lts-announce/2022/09/msg00007.html
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-0367