CVE-2024-45287: Multiple vulnerabilities in libnv
A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required for the parsed data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45287?
The severity of CVE-2024-45287 is classified as critical due to the potential for integer overflow and buffer allocation issues.
How do I fix CVE-2024-45287?
To fix CVE-2024-45287, update to the patched versions of FreeBSD provided in the security advisory.
What versions of FreeBSD are affected by CVE-2024-45287?
CVE-2024-45287 affects FreeBSD versions from 13.0 up to and including 13.3, and versions from 14.0 up to 14.1.
What impact does CVE-2024-45287 have on systems?
CVE-2024-45287 can potentially lead to memory corruption, denial of service, or arbitrary code execution due to improper buffer sizing.
Is there a known exploit for CVE-2024-45287?
As of now, there are no publicly disclosed exploits for CVE-2024-45287, but it remains a significant risk until patched.