CVE-2024-52065: Potential stack buffer write overflow in Persistence Service while parsing malicious environment variable on non-Windows systems
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-Windows (Persistence Service) allows Buffer Overflow via Environment Variables.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.1.2 before 6.1.2.21, from 5.3.1.40 before 5.3.1.41.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52065?
CVE-2024-52065 is classified as a critical severity vulnerability due to its potential to cause a buffer overflow.
How do I fix CVE-2024-52065?
To remediate CVE-2024-52065, upgrade RTI Connext Professional to version 7.3.0.2 or later, or apply necessary patches as provided by the vendor.
What versions of RTI Connext Professional are affected by CVE-2024-52065?
CVE-2024-52065 affects RTI Connext Professional versions from 7.0.0 before 7.3.0.2 and versions from 6.1.1.2 before 6.1.2.21.
What type of vulnerability is CVE-2024-52065?
CVE-2024-52065 is a buffer overflow vulnerability specifically caused by insufficient size checks during buffer copying operations.
Can CVE-2024-52065 be exploited remotely?
Yes, CVE-2024-52065 can potentially be exploited remotely through environment variables, increasing the risk of unauthorized access.