PT-2024-4371 · Mupdf+9 · Mupdf+9

Sebras

·

Published

2024-02-05

·

Updated

2025-11-17

·

CVE-2024-24258

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions freeglut version 3.4.0 mupdf version 1.23.9
Description The issue is related to a memory leak in the glutAddSubMenu function through the menuEntry variable. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For freeglut version 3.4.0, consider disabling the glutAddSubMenu function until a patch is available to prevent potential exploitation. For mupdf version 1.23.9, restrict access to the glutAddSubMenu function to minimize the risk of exploitation.

Exploit

Fix

DoS

Memory Leak

Weakness Enumeration

Related Identifiers

ALSA-2024:2366
ALSA-2024:3120
AZL-39708
AZL-43459
BDU:2024-04862
CESA-2024_3120
CVE-2024-24258
INFSA-2024_2366
INFSA-2024_3120
MGASA-2024-0165
OESA-2024-1174
RHSA-2024:2366
RHSA-2024:3120
RHSA-2024_2366
RHSA-2024_3120
RLSA-2024:2366
USN-7870-1

Affected Products

Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu
Freeglut
Mupdf