CVE-2024-42415

Public on 2024-10-03
Modified on 2024-10-07
Description
An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
8.4
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core libgsf 2024-11-01 ALAS2-2024-2681 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD CVSSv3 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H