CVE-2024-27507 โ€” Missing Release of Memory after Effective Lifetime in Liblas

Severity
7.5HIGHNVD
EPSS
0.1%
top 68.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 27

Description

libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

โ–ถNVDliblas/liblas1.8.1

Also affects: Fedora 38, 39, 40

๐Ÿ”ดVulnerability Details

3
CVEList
CVE-2024-27507: libLAS 1โ†—2024-02-27
โ–ถ
OSV
CVE-2024-27507: libLAS 1โ†—2024-02-27
โ–ถ
GHSA
GHSA-qjgm-wr4w-h2g9: libLAS 1โ†—2024-02-27
โ–ถ

๐Ÿ“‹Vendor Advisories

1
Red Hat
liblas: memory leak may lead to DoSโ†—2024-02-27
โ–ถ
CVE-2024-27507 โ€” Liblas vulnerability | cvebase