PT-2024-3009 · Uamqp+2 · Uamqp+2
Ericwolz
·
Published
2024-02-10
·
Updated
2025-02-14
·
CVE-2024-27099
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
uAMQP (affected versions not specified)
Description
The uAMQP library, used for AMQP 1.0 communication to Azure Cloud Services, contains an error related to the incorrect processing of an
AMQP VALUE failed state, which may cause a double free problem. This issue can potentially allow a remote attacker to execute arbitrary code, leading to a remote code execution (RCE) scenario.Recommendations
Update the submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987 to resolve the issue. As a temporary workaround, consider restricting the use of the
AMQP VALUE processing functionality until the update is applied.Exploit
Fix
RCE
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Suse
Uamqp