First published: Tue Aug 20 2024(Updated: )
cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vixie Cron | <9cc8ab1 | |
OpenBSD | >=7.4<=7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43688 is classified as a medium severity vulnerability due to the potential for memory corruption.
To fix CVE-2024-43688, upgrade your vixie cron to a version later than 9cc8ab1 as specified in the vulnerability report.
CVE-2024-43688 affects OpenBSD versions 7.4 and 7.5 that use vixie cron prior to the version 9cc8ab1.
CVE-2024-43688 is a heap-based buffer underflow vulnerability that can lead to memory corruption.
CVE-2024-43688 was introduced during a code refactoring in May 2023 in the vixie cron implementation.