Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.DIST
  • Bug#1102010: ros-dynamic-reconfigure: CVE-2024-39780

    From Salvatore Bonaccorso@21:1/5 to All on Thu Apr 3 23:30:01 2025
    Source: ros-dynamic-reconfigure
    Version: 1.7.3-1
    Severity: important
    Tags: security upstream
    Forwarded: https://github.com/ros/dynamic_reconfigure/pull/202
    X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
    Control: found -1 1.7.3-2

    Hi,

    The following vulnerability was published for ros-dynamic-reconfigure.

    CVE-2024-39780[0]:
    | A YAML deserialization vulnerability was found in the Robot
    | Operating System (ROS) 'dynparam', a command-line tool for getting,
    | setting, and deleting parameters of a dynamically configurable node,
    | affecting ROS distributions Noetic and earlier. The issue is caused
    | by the use of the yaml.load() function in the 'set' and 'get' verbs,
    | and allows for the creation of arbitrary Python objects. Through
    | this flaw, a local or remote user can craft and execute arbitrary
    | Python code. This issue has now been fixed for ROS Noetic via commit
    | 3d93ac13603438323d7e9fa74e879e45c5fe2e8e.


    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2024-39780
    https://www.cve.org/CVERecord?id=CVE-2024-39780
    [1] https://github.com/ros/dynamic_reconfigure/pull/202
    [2] https://github.com/ros/dynamic_reconfigure/commit/9975cc8b55b3039115da6662cc7279cc65303844

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Adam Fancher
      Thu May 22 20:51:38 2025
      from Winsted, Ct via Telnet
    • Jokke
      Thu May 22 20:13:05 2025
      from Be via Telnet
    • Jokke
      Thu May 22 15:51:38 2025
      from Be via Telnet
    • Adam Fancher
      Thu May 22 15:27:52 2025
      from Winsted, Ct via Telnet
    • Skwx
      Thu May 22 15:25:23 2025
      from London, Uk via Telnet
    • Jokke
      Thu May 22 11:19:03 2025
      from Be via Telnet
    • Jokke
      Thu May 22 10:58:11 2025
      from Be via Telnet
    • Jokke
      Thu May 22 10:43:16 2025
      from Be via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 481
    Nodes: 16 (2 / 14)
    Uptime: 14:44:19
    Calls: 9,540
    Calls today: 8
    Files: 13,653
    Messages: 6,139,624
    Posted today: 1

© >>> Magnum BBS <<<, 2025