PT-2024-25777 · Openbsd · Openbsd

Nikolascw

·

Published

2024-05-21

·

Updated

2024-07-03

·

CVE-2024-34274

CVSS v3.1

3.9

Low

VectorAV:P/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenBD version 20210306203917-6cbe797
Description The issue concerns the deserialization of untrusted data in OpenBD, specifically affecting the cookies bdglobals and bdclient spot that use serialized data. This can be exploited to execute arbitrary code on the system. It's noted that this vulnerability only affects products that are no longer supported by the maintainer.
Recommendations For OpenBD version 20210306203917-6cbe797, as a temporary workaround, consider restricting access to the cookies bdglobals and bdclient spot to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-34274

Affected Products

Openbsd