CVE-2024-44910: High severity cryptolib vulnerability
Published Sep 27, 2024
·Updated
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (cryptoaos.c).
Affected Software
1 affected component
nasa CryptoLib=1.3.0
Event History
Sep 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-44910?
CVE-2024-44910 is classified as a high-severity vulnerability due to the potential for an Out-of-Bounds read.
2
How do I fix CVE-2024-44910?
To mitigate CVE-2024-44910, upgrade to a patched version of NASA CryptoLib where the Out-of-Bounds read issue is resolved.
3
What systems are affected by CVE-2024-44910?
CVE-2024-44910 affects version 1.3.0 of NASA CryptoLib.
4
What specific component in NASA CryptoLib is vulnerable in CVE-2024-44910?
The vulnerability in CVE-2024-44910 is specifically found in the AOS subsystem, particularly in the file crypto_aos.c.
5
Can CVE-2024-44910 lead to data leakage?
Yes, CVE-2024-44910 could potentially lead to data leakage due to the nature of the Out-of-Bounds read.