First published: Tue Jan 14 2025(Updated: )
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.
Credit: secure@blackberry.com
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry QNX Software Development Platform | >=7.0<=8.0 | |
BlackBerry QNX Software Development Platform | =7.0 | |
BlackBerry QNX Software Development Platform | =7.1 | |
BlackBerry QNX Software Development Platform | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48856 is considered to have a high severity due to its potential to cause denial-of-service conditions and execute arbitrary code.
To fix CVE-2024-48856, update your QNX Software Development Platform to the latest version that resolves this vulnerability.
CVE-2024-48856 affects users of the QNX Software Development Platform versions 7.0, 7.1, and 8.0.
CVE-2024-48856 is an out-of-bounds write vulnerability specifically in the PCX image codec.
Yes, CVE-2024-48856 can be exploited by an unauthenticated attacker, potentially leading to remote code execution.