PT-2024-3009 · Uamqp+2 · Uamqp+2

Ericwolz

·

Published

2024-02-10

·

Updated

2025-02-14

·

CVE-2024-27099

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions uAMQP (affected versions not specified)
Description The uAMQP library, used for AMQP 1.0 communication to Azure Cloud Services, contains an error related to the incorrect processing of an AMQP VALUE failed state, which may cause a double free problem. This issue can potentially allow a remote attacker to execute arbitrary code, leading to a remote code execution (RCE) scenario.
Recommendations Update the submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987 to resolve the issue. As a temporary workaround, consider restricting the use of the AMQP VALUE processing functionality until the update is applied.

Exploit

Fix

RCE

Double Free

Weakness Enumeration

Related Identifiers

AZL-35447
AZL-35471
BDU:2024-03191
CVE-2024-27099
GHSA-6RH4-FJ44-V4JJ
OPENSUSE-SU-2024:13729-1
SUSE-SU-2024:0947-1
SUSE-SU-2024_0947-1

Affected Products

Debian
Suse
Uamqp