CVE-2024-27232
published 2024-04-05CVE-2024-27232: In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.09%
0.5th percentile
In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x8rm-m93r-jqp2: In asn1_ec_pkey_parse of asn1_common
ghsa_unreviewed·2024-04-05
CVE-2024-27232 [MEDIUM] CWE-476 GHSA-x8rm-m93r-jqp2: In asn1_ec_pkey_parse of asn1_common
In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-27232: In asn1_ec_pkey_parse of asn1_common
osv·2024-04-01
CVE-2024-27232 CVE-2024-27232: In asn1_ec_pkey_parse of asn1_common
In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-05
Published