integer overflow in packed libnv can lead to buffer allocation issue
CVE-2024-45287
7.5HIGH
What is CVE-2024-45287?
The vulnerability identified in the packed libnv structure of FreeBSD can lead to an integer overflow resulting from a maliciously crafted value. This flaw can enable attackers to manipulate buffer sizes, causing smaller-than-required buffers to be allocated during data parsing, which may result in potential data loss or corruption. Users of affected versions must review their systems and apply necessary patches to mitigate this risk.
Affected Version(s)
FreeBSD 14.1-RELEASE
FreeBSD 14.0-RELEASE
FreeBSD 13.3-RELEASE
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Synacktiv
Taylor R Campbell (NetBSD)