6.9 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): Low (L)
- Vulnerable System Impact Integrity (VI): Low (L)
- Vulnerable System Impact Availability (VA): Low (L)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Exploit Maturity (E): Not Defined (X)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
- Modified Vulnerable System Impact Integrity (MVI): Low (L)
- Modified Vulnerable System Impact Availability (MVA): Low (L)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
Activity log
- Created suggestion
NASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflow
A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way.
References
-
VDB-397028 | NASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflow technical-descriptionvdb-entry
-
-
CVE-2026-82478 | CVE Analysis and Report third-party-advisory
-
Submit #888016 | NASA Trick 19.6.0 Buffer Overflow third-party-advisory
Affected products
- ==19.6.0
Matching in nixpkgs
pkgs.trickle
Lightweight userspace bandwidth shaper
-
nixos-unstable 1.07-unstable-2019-10-03
- nixpkgs-unstable 1.07-unstable-2019-10-03
- nixos-unstable-small 1.07-unstable-2019-10-03
-
nixos-26.05 1.07-unstable-2019-10-03
- nixos-26.05-small 1.07-unstable-2019-10-03
- nixpkgs-26.05-darwin 1.07-unstable-2019-10-03
pkgs.pdftricks
Simple, efficient application for small manipulations in PDF files using Ghostscript
pkgs.trickster
Reverse proxy cache and time series dashboard accelerator
pkgs.winetricks
Script to install DLLs needed to work around problems in Wine
pkgs.protontricks
Simple wrapper for running Winetricks commands for Proton-enabled games
pkgs.trickest-cli
CLI tool to execute Trickest workflows
pkgs.gnomeExtensions.window-tricks
Focus, snap, switch and resize windows with keybinds, clipboard history indicator and app tray indicator.
pkgs.python313Packages.json-tricks
Extra features for Python JSON handling
pkgs.python314Packages.json-tricks
Extra features for Python JSON handling
pkgs.python313Packages.electrickiwi-api
Python library for interfacing with the Electric Kiwi power company API
Package maintainers
-
@honnip Jung seungwoo <me@honnip.page>
-
@theobori Théo Bori <theobori@disroot.org>
-
@kira-bruneau Kira Bruneau <kira.bruneau@pm.me>
-
@JamieMagee Jamie Magee <jamie.magee@gmail.com>
-
@bcdarwin Ben Darwin <bcdarwin@gmail.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@1000101 Jan Hrnko <b1000101@pm.me>