CVE-2023-24604

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published May 29, 2023
Updated: Jan 14, 2025

Summary

CVE-2023-24604 is a vulnerability affecting OX App Suite before version 7.10.6-rev37. This issue allows a maliciously crafted iCal feed to provide an unlimited amount of header data during download. The software fails to check the length of HTTP headers, potentially leading to memory exhaustion or denial-of-service attacks. The vulnerability poses a significant risk, especially in environments where users frequently download iCal feeds. It is recommended that affected organizations upgrade to the latest version of OX App Suite to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share