PT-2024-4372 · Mupdf+9 · Mupdf+9

Sebras

·

Published

2024-02-05

·

Updated

2025-11-17

·

CVE-2024-24259

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions freeglut versions 3.4.0 and earlier mupdf version 1.23.9
Description The issue is related to a memory leak via the menuEntry variable in the glutAddMenuEntry() function. This can potentially allow a remote attacker to cause a denial of service.
Recommendations For freeglut versions 3.4.0 and earlier, consider disabling the glutAddMenuEntry() function until a patch is available. For mupdf version 1.23.9, restrict access to the glutAddMenuEntry() function to minimize the risk of exploitation. Avoid using the menuEntry variable in the affected function until the issue is resolved.

Exploit

Fix

DoS

Memory Leak

Weakness Enumeration

Related Identifiers

ALSA-2024:2366
ALSA-2024:3120
AZL-39694
AZL-43438
BDU:2024-04863
CESA-2024_3120
CVE-2024-24259
INFSA-2024_2366
INFSA-2024_3120
MGASA-2024-0165
OESA-2024-1174
RHSA-2024:2366
RHSA-2024:3120
RHSA-2024_2366
RHSA-2024_3120
RLSA-2024:2366
USN-7870-1

Affected Products

Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu
Freeglut
Mupdf