Apache Celix is an implementation of the OSGi specification adapted to C and C++. It is a framework to develop (dynamic) modular software applications using component and/or service-oriented programming.
Apache Celix suffers from a heap-based buffer overflow vulnerability in its remote-services Endpoint Description Extender (EDEF) parser. Attacker-influenced endpoint-descriptor content is concatenated into a heap buffer without adequate bounds checking, corrupting adjacent heap memory. On deployments that use remote-services discovery, a crafted descriptor can crash the process or lead to code execution.