CVE-2024-42415

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 3, 2024
Updated: Nov 21, 2024
CWE ID 190

Summary

CVE-2024-42415 is an integer overflow vulnerability discovered in the Compound Document Binary File format parser of GNOME Project's G Structured File Library (libgsf) version 1.14.52. Maliciously crafted files can cause an integer overflow in the sector allocation table processing, resulting in a heap-based buffer overflow. Attackers can exploit this vulnerability to execute arbitrary code by providing a specially crafted file to the affected system. This issue poses a serious security risk and requires immediate attention and patching from users and administrators.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Gnome Libgsf

Affected Vendors

  • GNOME Project