CVE-2024-52061: Potential stack buffer overflow when parsing an XML type
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries, Queuing Service, Recording Service, Routing Service) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.5, from 6.1.0 before 6.1.2.21, from 6.0.0 before 6.0.1.40, from 5.0.0 before 5.3.1.45.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52061?
CVE-2024-52061 is classified as a buffer overflow vulnerability which can lead to potential code execution.
How do I fix CVE-2024-52061?
To mitigate CVE-2024-52061, upgrade to RTI Connext Professional version 7.5.0 or later.
Which versions of RTI Connext Professional are affected by CVE-2024-52061?
CVE-2024-52061 affects RTI Connext Professional versions from 5.0.0 up to, but not including, 7.5.0.
What components of RTI Connext Professional are impacted by CVE-2024-52061?
CVE-2024-52061 impacts the Core Libraries, Queuing Service, Recording Service, and Routing Service within RTI Connext Professional.
Can CVE-2024-52061 lead to data loss?
Yes, CVE-2024-52061 can potentially lead to data loss due to undefined behavior caused by the buffer overflow.