CVE-2024-43688: High severity vixie cron vulnerability
Published Aug 20, 2024
·Updated
cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.
Affected Software
2 affected components
OpenBSD vixie cron<9cc8ab1
OpenBSD OpenBSD>=7.4<=7.5
Event History
Aug 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43688?
CVE-2024-43688 is classified as a medium severity vulnerability due to the potential for memory corruption.
2
How do I fix CVE-2024-43688?
To fix CVE-2024-43688, upgrade your vixie cron to a version later than 9cc8ab1 as specified in the vulnerability report.
3
What systems are affected by CVE-2024-43688?
CVE-2024-43688 affects OpenBSD versions 7.4 and 7.5 that use vixie cron prior to the version 9cc8ab1.
4
What type of vulnerability is CVE-2024-43688?
CVE-2024-43688 is a heap-based buffer underflow vulnerability that can lead to memory corruption.
5
When was CVE-2024-43688 introduced?
CVE-2024-43688 was introduced during a code refactoring in May 2023 in the vixie cron implementation.