CVE-2024-52062: Potential stack buffer write overflow in Connext applications while parsing malicious XML types document
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0 before 7.3.0.5, from 6.1.0 before 6.1.2.21, from 6.0.0 before 6.0.1.40, from 5.0.0 before 5.3.1.45.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52062?
CVE-2024-52062 is classified as a high severity vulnerability that can lead to buffer overflow issues.
How do I fix CVE-2024-52062?
To address CVE-2024-52062, it is recommended to upgrade RTI Connext Professional to version 7.3.0.5 or later, or to the appropriate patched version depending on your current version.
Which versions of RTI Connext Professional are affected by CVE-2024-52062?
CVE-2024-52062 affects RTI Connext Professional versions from 5.0.0 to 5.3.1.45, from 6.0.0 to 6.1.2.21, and versions from 7.0.0 to 7.3.0.5.
What type of vulnerability is CVE-2024-52062?
CVE-2024-52062 is a 'Classic Buffer Overflow' vulnerability, specifically a buffer copy issue that does not check the size of input.
What are the potential impacts of CVE-2024-52062?
The potential impacts of CVE-2024-52062 include overflow variables and tags, which may lead to application crashes or unauthorized code execution.