Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-42982: BKG Professional NtripCaster

BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can be used for UDP amplification attacks. Normally, only authenticated streaming data will be provided over UDP and not the sourcetable.

CVE
#linux#debian#red_hat#auth

BKG Professional NtripCaster (Datasheet)****Application and Specifications

The BKG Professional NtripCaster allows the dissemination of GNSS real-time data streams via internet. The software supports the Ntrip internet protocol in version 1 and 2. For more details on the Ntrip protocol, please see here.
The software has been developed within the framework of the EUREF-IP project. It is based on the ICECAST Internet Radio software written in C programming language under GNU General Public License (GPL). The caster is running on Linux systems and has been tested successfully on various distributions, such as Suse, Debian, Gentoo, and Red Hat. The software supports more than 100 NtripServers and more than 2000 listening NtripClients simultaneously. There are more than 100 operational installations worldwide. For technical details, see the manual.

Order and Delivery

The BKG Professional NtripCaster can be purchased at a price of 1000€. This includes delivery of the software including the source code in C programming language. Installation or operation support is not included. Software developments and bug fixes are provided at no additional costs.

Please fill in the order form below. Submit the form and you will receive an invoice by BKG. As soon as the BKG has received your payment the software will be delivered by e-mail including installation documentation, software documentation and source code.

Contact

Federal Agency for Cartography and Geodesy (BKG)
Section Satellite Navigation
Richard-Strauss-Allee 11, 60598 Frankfurt / Main
Germany
E-Mail: [email protected]

Disclaimer: BKG does not give any warranty regarding the function of the BKG Professional NtripCaster. Moreover, the BKG disclaims any liability nor responsibility to any person or entity with respect to any loss or damage caused, or alleged to be caused, directly or indirectly by the use of BKG Professional NtripCaster.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907