CVE-2024-52063: Potential stack buffer write overflow in Connext applications while parsing malicious XML types document
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries, Routing Service) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0 before 7.3.0.5, from 6.1.0 before 6.1.2.21, from 6.0.0 before 6.0.1.40, from 5.0.0 before 5.3.1.45.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52063?
CVE-2024-52063 is rated as a medium severity vulnerability due to its potential to cause buffer overflow incidents.
How do I fix CVE-2024-52063?
To fix CVE-2024-52063, upgrade RTI Connext Professional to version 7.3.0.5 or later, or to version 6.1.2.21 or later.
Which versions of RTI Connext Professional are affected by CVE-2024-52063?
CVE-2024-52063 affects RTI Connext Professional versions 5.0.0 to 5.3.1.45, 6.0.0 to 6.0.1.40, 6.1.0 to 6.1.2.21, and 7.0.0 to 7.3.0.5.
What types of vulnerabilities does CVE-2024-52063 represent?
CVE-2024-52063 represents a buffer overflow vulnerability due to buffer copying without size checks.
What are the implications of exploiting CVE-2024-52063?
Exploiting CVE-2024-52063 could allow attackers to overwrite memory, potentially leading to data corruption or arbitrary code execution.