PT-2024-4371 · Mupdf+9 · Mupdf+9
Sebras
·
Published
2024-02-05
·
Updated
2025-11-17
·
CVE-2024-24258
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
freeglut version 3.4.0
mupdf version 1.23.9
Description
The issue is related to a memory leak in the
glutAddSubMenu function through the menuEntry variable. This can be exploited by a remote attacker to cause a denial of service.Recommendations
For freeglut version 3.4.0, consider disabling the
glutAddSubMenu function until a patch is available to prevent potential exploitation.
For mupdf version 1.23.9, restrict access to the glutAddSubMenu function to minimize the risk of exploitation.Exploit
Fix
DoS
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu
Freeglut
Mupdf