CVE-2024-39835: Unsafe use of eval() method in roslaunch tool
A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() method to process user-supplied, unsanitized parameter values within the substitution args mechanism, which roslaunch evaluates before launching a node. This flaw allows attackers to craft and execute arbitrary Python code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39835?
CVE-2024-39835 is classified as a high severity vulnerability due to the potential for code injection, which can lead to unauthorized execution of arbitrary code.
How do I fix CVE-2024-39835?
To fix CVE-2024-39835, users should avoid using the eval() method with unsanitized user input and upgrade to a secure version of ROS that does not include this vulnerability.
What versions of ROS are affected by CVE-2024-39835?
CVE-2024-39835 affects all versions of the Robot Operating System (ROS) Noetic Ninjemys and earlier.
What is the impact of CVE-2024-39835 on my system?
The impact of CVE-2024-39835 could allow an attacker to execute arbitrary code on the system running the affected ROS version, potentially compromising system integrity.
Is there a patch available for CVE-2024-39835?
As of now, a specific patch for CVE-2024-39835 has not been released; users are advised to follow best practices and upgrade their RO S distributions where necessary.