PT-2024-3069 · Uamqp+2 · Uamqp+2

Published

2024-02-05

·

Updated

2024-11-22

·

CVE-2024-25110

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions uAMQP (affected versions not specified)
Description The issue is related to the open get offered capabilities function in the uAMQP library, which is a general-purpose C library for AMQP 1.0. A memory allocation failure during this function call may cause a use-after-free issue. If a client calls this function during connection communication, it may lead to remote code execution. There are no known workarounds for this issue.
Recommendations Update the submodule with commit 30865c9c to resolve the issue. As a temporary workaround, consider disabling the open get offered capabilities function until a patch is available.

Exploit

Fix

RCE

Use After Free

Code Injection

Weakness Enumeration

Related Identifiers

AZL-34349
AZL-34556
BDU:2024-03262
CVE-2024-25110
GHSA-C646-4WHF-R67V
OPENSUSE-SU-2024:13682-1
SUSE-SU-2024:0591-1
SUSE-SU-2024_0591-1

Affected Products

Debian
Suse
Uamqp