Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-25110

Опубликовано: 10 фев. 2024
Источник: redhat
CVSS3: 6
EPSS Низкий

Описание

The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to update the submodule with commit 30865c9c. There are no known workarounds for this vulnerability.

An integer overflow vulnerability was found in python-uamqp-azure affecting the embedded azure-uamqp-c library at the message.c file. If some uncommon conditions are met, an authenticated user may cause remote code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2python3x-uamqpNot affected
Red Hat Ansible Automation Platform 2python-uamqpNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2272485python-uamqp-azure: Integer overflow at message.c

EPSS

Процентиль: 77%
0.01024
Низкий

6 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 2 года назад

The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to update the submodule with commit `30865c9c`. There are no known workarounds for this vulnerability.

CVSS3: 9.8
nvd
почти 2 года назад

The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to update the submodule with commit `30865c9c`. There are no known workarounds for this vulnerability.

CVSS3: 8.1
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 9.8
debian
почти 2 года назад

The UAMQP is a general purpose C library for AMQP 1.0. During a call t ...

suse-cvrf
почти 2 года назад

Security update for python-uamqp

EPSS

Процентиль: 77%
0.01024
Низкий

6 Medium

CVSS3