PT-2024-36397 · Dante+3 · Dante+3

Igor Medovolkin

·

Published

2024-12-16

·

Updated

2025-11-20

·

CVE-2024-54662

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Dante versions 1.4.0 through 1.4.3
Description The issue is related to incorrect access control for some sockd.conf configurations involving the socksmethod. This problem affects certain settings and can lead to unauthorized access.
Recommendations For versions 1.4.0 through 1.4.3, update to version 1.4.4 to resolve the issue. As a temporary workaround, consider restricting access to configurations involving the socksmethod until a patch is available.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2025-14768
ALT-PU-2025-6567
BDU:2025-07336
CVE-2024-54662
OPENSUSE-SU-2025:0030-1
OPENSUSE-SU-2025:15132-1

Affected Products

Alt Linux
Dante
Debian
Red Os