CVE-2024-27632: High severity gnu savane vulnerability
Published Apr 8, 2024
·Updated
An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the formid in the formheader() function.
Affected Software
2 affected components
GNU Savane<3.12
GNU Savane<3.13
Event History
Apr 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27632?
CVE-2024-27632 has been rated as a medium severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2024-27632?
You can fix CVE-2024-27632 by updating GNU Savane to version 3.13 or later, where this vulnerability has been patched.
3
Who is affected by CVE-2024-27632?
CVE-2024-27632 affects users of GNU Savane version 3.12 and earlier.
4
What type of attack is enabled by CVE-2024-27632?
CVE-2024-27632 allows a remote attacker to escalate privileges by exploiting the form_id in the form_header() function.
5
Can CVE-2024-27632 be exploited remotely?
Yes, CVE-2024-27632 can be exploited remotely, making it a critical concern for users of the affected software.