CVE-2019-13445: Ros Ros-Comm
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. parseOptions() in tools/rosbag/src/record.cpp has an integer overflow when a crafted split option can be entered on the command line.
Affected products
- Ros Ros-Comm: up to and including 1.14.3
Published 2019-12-30. Last modified 2026-06-17.