CVE-2024-36474

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 3, 2024
Updated: Nov 21, 2024
CWE ID 190

Summary

CVE-2024-36474 is an integer overflow vulnerability affecting the Compound Document Binary File format parser in the GNOME Project G Structured File Library (libgsf) version 1.14.52. A specially crafted file can cause an integer overflow during processing, resulting in an out-of-bounds index being used when handling arrays. This issue grants an attacker the ability to execute arbitrary code by providing a malicious file to exploit the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Gnome Libgsf

Affected Vendors

  • GNOME Project