CVE-2024-24246: Buffer Overflow
Published Feb 29, 2024
·Updated
Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::sharedcount() function at /bits/sharedptrbase.h.
Affected Software
7 affected componentsFixes available
ubuntu/qpdf<11.5.0-1ubuntu1.1
11.5.0-1ubuntu1.1
ubuntu/qpdf<11.9.0-1
11.9.0-1
debian/qpdf<=11.3.0-1+deb12u1
8.4.0-28.4.0-2+deb10u110.1.0-111.9.0-2
Qpdf Project Qpdf=11.9.0
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Fedoraproject Fedora=40
Remediation
Event History
Feb 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 29, 2024
Data Sourced
via Launchpad·01:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-24246?
CVE-2024-24246 is classified as a high severity vulnerability due to its potential to cause application crashes.
2
How do I fix CVE-2024-24246?
To fix CVE-2024-24246, update qpdf to version 11.9.0-2 or later from the repository of your Linux distribution.
3
What versions of qpdf are affected by CVE-2024-24246?
CVE-2024-24246 affects qpdf versions 11.9.0 and potentially earlier versions depending on the specific package source.
4
Can CVE-2024-24246 be exploited remotely?
Yes, CVE-2024-24246 can be exploited by attackers remotely to crash the application, causing denial of service.
5
What systems are affected by CVE-2024-24246?
CVE-2024-24246 affects systems running qpdf version 11.9.0 on Ubuntu, Debian, and Fedora distributions.