CVE-2024-56375
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Dec 22, 2024
Updated: Dec 26, 2024
CWE ID 191
Summary
CVE-2024-56375 is an integer underflow vulnerability affecting Fort versions 1.6.3 and 1.6.4. A maliciously crafted RPKI repository can serve a Manifest RPKI object with an empty fileList, causing Fort to dereference and write to an out-of-bounds array during a shuffle attempt. This results in an infinite loop, leading to a near-guaranteed crash as Fort attempts to overshuffle an array that doesn't exist. The vulnerability can be exploited via rsync or RRDP.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share