CVE-2024-29937: Code Injection
Published Mar 21, 2024
·Updated
NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.
Affected Software
4 affected components
OpenBSD OpenBSD<=7.4
FreeBSD FreeBSD<=14.0-RELEASE
FreeBSD FreeBSD=14.0
OpenBSD OpenBSD<=7.4
Event History
Mar 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Apr 11, 2024
Data Sourced
via NVD·01:25 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29937?
CVE-2024-29937 is a critical vulnerability that allows remote attackers to execute arbitrary code.
2
How does CVE-2024-29937 affect OpenBSD and FreeBSD?
CVE-2024-29937 affects OpenBSD versions up to 7.4 and FreeBSD versions up to 14.0-RELEASE.
3
What systems are vulnerable to CVE-2024-29937?
The vulnerability is present in NFS implementations within BSD derived codebases.
4
How can I mitigate CVE-2024-29937?
Mitigation for CVE-2024-29937 involves applying security patches and updates provided by OpenBSD and FreeBSD.
5
Is there a workaround for CVE-2024-29937?
Currently, there is no specific workaround for CVE-2024-29937, so updating the affected systems is recommended.