PT-2024-26089 · Unknown · Librtppayload.So

Skyh1Ll

·

Published

2024-10-07

·

Updated

2024-10-30

·

CVE-2024-34668

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions librtppayload.so versions prior to SMR Oct-2024 Release 1
Description The issue is an out-of-bounds write in parsing h.263 format, which allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this issue.
Recommendations For versions prior to SMR Oct-2024 Release 1, update to SMR Oct-2024 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the librtppayload.so library until a patch is available.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2024-34668

Affected Products

Librtppayload.So