CVE-2024-39289: Unsafe use of eval() method in rosparam tool
A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability stems from the use of the eval() function to process unsanitized, user-supplied parameter values via special converters for angle representations in radians. This flaw allowed attackers to craft and execute arbitrary Python code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39289?
CVE-2024-39289 is classified as a high severity code execution vulnerability.
How do I fix CVE-2024-39289?
To fix CVE-2024-39289, upgrade to a later version of the Robot Operating System that does not include the vulnerability.
What versions of Robot Operating System are affected by CVE-2024-39289?
CVE-2024-39289 affects the Robot Operating System Noetic Ninjemys and earlier versions.
What causes the CVE-2024-39289 vulnerability?
The CVE-2024-39289 vulnerability is caused by the use of the eval() function to process unsanitized user-supplied parameter values.
Are there any known exploits for CVE-2024-39289?
There are currently no specific exploits publicly available for CVE-2024-39289.