CVE-2024-49749: Integer Overflow
Published Jan 6, 2025
·Updated
In DGifSlurp of dgiflib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
6 affected components
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android=14.0
Google Android=15.0
Google Android
Event History
Jan 6, 2025
CVE Published
via Android·12:00 AM
Jan 21, 2025
CVE Published
via MITRE·11:04 PM
Data Sourced
via MITRE·11:04 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-49749?
CVE-2024-49749 is rated as critical due to its potential for remote code execution.
2
How do I fix CVE-2024-49749?
To resolve CVE-2024-49749, ensure that you update your Android device to the latest security patch from Google.
3
What kind of exploitation is possible with CVE-2024-49749?
CVE-2024-49749 could be exploited for remote code execution without requiring user interaction.
4
Which software versions are affected by CVE-2024-49749?
CVE-2024-49749 affects specific versions of Android operating systems that utilize the DGifSlurp function in dgif_lib.c.
5
Is user interaction required to exploit CVE-2024-49749?
No, user interaction is not needed for the exploitation of CVE-2024-49749.