PT-2024-3069 · Uamqp+2 · Uamqp+2
Published
2024-02-05
·
Updated
2024-11-22
·
CVE-2024-25110
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
uAMQP (affected versions not specified)
Description
The issue is related to the
open get offered capabilities function in the uAMQP library, which is a general-purpose C library for AMQP 1.0. A memory allocation failure during this function call may cause a use-after-free issue. If a client calls this function during connection communication, it may lead to remote code execution. There are no known workarounds for this issue.Recommendations
Update the submodule with commit
30865c9c to resolve the issue.
As a temporary workaround, consider disabling the open get offered capabilities function until a patch is available.Exploit
Fix
RCE
Use After Free
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Suse
Uamqp