PT-2024-7273 · Gnome+6 · Libgsf+6

A Member

·

Published

2024-09-03

·

Updated

2024-12-05

·

CVE-2024-42415

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: GNOME Project G Structured File Library (libgsf) version 1.14.52
Description: An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Recommendations: For version 1.14.52 of the GNOME Project G Structured File Library (libgsf), consider disabling the Compound Document Binary File format parser until a patch is available. Restrict access to files in the Compound Document Format to minimize the risk of exploitation. Avoid using the library to process untrusted files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15101
AZL-50061
AZL-50088
BDU:2024-08625
CVE-2024-42415
DLA-3911-1
DSA-5786-1
MGASA-2024-0337
OESA-2024-2221
OPENSUSE-SU-2024_3920-1
OPENSUSE-SU-2024_3922-1
ROSA-SA-2024-2538
SUSE-SU-2024:3770-1
SUSE-SU-2024:3920-1
SUSE-SU-2024:3921-1
SUSE-SU-2024:3922-1
USN-7062-1
USN-7062-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu
Libgsf