Integer Overflow Vulnerability in GNOME Project's G Structured File Library (libgsf)
CVE-2024-36474
7.8HIGH
What is CVE-2024-36474?
An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. This vulnerability is triggered by processing specially crafted files, which can lead to an out-of-bounds index being used when accessing arrays. This scenario creates a pathway for potential arbitrary code execution. Attackers can exploit this flaw by providing crafted files, causing unintended consequences within the affected software.
Affected Version(s)
G Structured File Library (libgsf) 1.14.52