PT-2024-16649 · Openbsd · Openbsd

Published

2024-12-05

·

Updated

2025-09-23

·

CVE-2024-10933

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenBSD versions 7.4 through 7.5 before errata 009 and 022
Description The issue arises from improper validation of readdir names, allowing unexpected directory traversal on untrusted file systems when a '/' is encountered. This can be mitigated by excluding any '/' in readdir name validation.
Recommendations For OpenBSD version 7.4, apply errata 022 to resolve the issue. For OpenBSD version 7.5, apply errata 009 to resolve the issue.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-10933

Affected Products

Openbsd