PT-2024-4372 · Mupdf+9 · Mupdf+9
Sebras
·
Published
2024-02-05
·
Updated
2025-11-17
·
CVE-2024-24259
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
freeglut versions 3.4.0 and earlier
mupdf version 1.23.9
Description
The issue is related to a memory leak via the
menuEntry variable in the glutAddMenuEntry() function. This can potentially allow a remote attacker to cause a denial of service.Recommendations
For freeglut versions 3.4.0 and earlier, consider disabling the
glutAddMenuEntry() function until a patch is available.
For mupdf version 1.23.9, restrict access to the glutAddMenuEntry() function to minimize the risk of exploitation.
Avoid using the menuEntry variable in the affected function until the issue is resolved.Exploit
Fix
DoS
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu
Freeglut
Mupdf