CVE-2024-48855

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 125

Summary

CVE-2024-48855 is a newly disclosed vulnerability affecting QNX SDP versions 8.0, 7.1, and 7.0. This out-of-bounds read issue in the TIFF image codec can be exploited by unauthenticated attackers. By manipulating specially crafted TIFF image files, they can cause the affected process to read memory outside of its intended bounds, potentially leading to information disclosure. This vulnerability poses a security risk and requires immediate attention from QNX SDP users to apply the available patch or update.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share