{ "schema_version": "1.4.0", "id": "GHSA-hjqf-54rq-5c9j", "modified": "2022-05-24T16:50:38Z", "published": "2022-05-24T16:50:38Z", "aliases": [ "CVE-2019-1010073" ], "details": "BACnet Stack bacserv 0.9.1 and 0.8.5 is affected by: Buffer Overflow. The impact is: exploit was not explored. The component is: bacserv BVLC forwarded NPDU. bvlc_bdt_forward_npdu() calls bvlc_encode_forwarded_npdu() which copies the content from the request into a local in the bvlc_bdt_forward_npdu() stack frame and clobbers the canary. The attack vector is: A BACnet/IP device with BBMD enabled based on this library connected to IP network. The fixed version is: 0.8.6.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-1010073" }, { "type": "WEB", "url": "https://sourceforge.net/p/bacnet/bugs/55" }, { "type": "WEB", "url": "https://sourceforge.net/p/bacnet/code/3169" } ], "database_specific": { "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-07-18T14:15:00Z" } }