CVE-2024-36474
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Oct 3, 2024
Updated: Nov 21, 2024
CWE ID 190
Summary
CVE-2024-36474 is an integer overflow vulnerability affecting the Compound Document Binary File format parser in the GNOME Project G Structured File Library (libgsf) version 1.14.52. A specially crafted file can cause an integer overflow during processing, resulting in an out-of-bounds index being used when handling arrays. This issue grants an attacker the ability to execute arbitrary code by providing a malicious file to exploit the vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Gnome Libgsf
Affected Vendors
- GNOME Project