PT-2024-23959 · Unknown · Libstatssocket
Published
2024-06-01
·
Updated
2024-12-17
·
CVE-2024-31311
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libstatssocket (affected versions not specified)
Description
The issue is related to a missing bounds check in the
increment annotation count function of stats event.c, which can lead to a possible out of bounds write. This could result in local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation. The vulnerability can be triggered when user inputs data into a StatsD event, which is then processed without boundary checks, potentially causing a heap buffer overflow.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libstatssocket