PT-2024-35112 · Real Time Innovations · Rti Connext Professional
Published
2024-12-13
·
Updated
2025-10-02
·
CVE-2024-52061
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RTI Connext Professional versions 5.0.0 through 5.3.1.45
RTI Connext Professional versions 6.0.0 through 6.0.1.40
RTI Connext Professional versions 6.1.0 through 6.1.2.21
RTI Connext Professional versions 7.0.0 through 7.3.0.5
RTI Connext Professional versions 7.4.0 through 7.5.0
Description
The issue is a 'Classic Buffer Overflow' vulnerability due to buffer copy without checking the size of the input. This allows for the overflow of variables and tags. It affects the Core Libraries, Queuing Service, Recording Service, and Routing Service of RTI Connext Professional.
Recommendations
For versions 5.0.0 through 5.3.1.45, update to a version later than 5.3.1.45.
For versions 6.0.0 through 6.0.1.40, update to a version later than 6.0.1.40.
For versions 6.1.0 through 6.1.2.21, update to a version later than 6.1.2.21.
For versions 7.0.0 through 7.3.0.5, update to a version later than 7.3.0.5.
For versions 7.4.0 through 7.5.0, update to a version later than 7.5.0.
As a temporary workaround, consider restricting access to the affected services until a patch is available.
Fix
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rti Connext Professional