First published: Wed Sep 18 2024(Updated: )
Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MeterBandList::unpack. This issue affects libfluid: 0.1.0.
Credit: prodsec@nozominetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Opennetworking Libfluid Msg | =0.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31185 has been classified as a moderate severity vulnerability due to its potential impact on software stability.
To fix CVE-2024-31185, upgrade the libfluid library to version 0.1.1 or later where the vulnerability has been addressed.
CVE-2024-31185 can lead to a NULL pointer dereference, potentially causing application crashes in systems using libfluid version 0.1.0.
Yes, CVE-2024-31185 can be exploited remotely if the affected libfluid application is exposed to untrusted input.
The affected component related to CVE-2024-31185 is the libfluid_msg module of the libfluid library, specifically the fluid_msg::of13::MeterBandList::unpack routine.