CVE-2024-30949: Integer Overflow
Published Aug 20, 2024
·Updated
An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the gettimeofday function.
Affected Software
1 affected component
Newlib Project Newlib=4.3.0
Remediation
Event History
Aug 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30949?
CVE-2024-30949 is classified as a high severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2024-30949?
To fix CVE-2024-30949, it is recommended to update Newlib to version 4.3.1 or later to mitigate the vulnerability.
3
What software versions are affected by CVE-2024-30949?
CVE-2024-30949 specifically affects Newlib version 4.3.0.
4
What type of vulnerability is CVE-2024-30949?
CVE-2024-30949 is an arbitrary code execution vulnerability caused by improper time unit scaling in the _gettimeofday function.
5
Who can be impacted by CVE-2024-30949?
Any application or system utilizing Newlib version 4.3.0 may be at risk of exploitation due to CVE-2024-30949.