CVE-2024-30949
published 2024-08-20CVE-2024-30949: An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.76%
51.7th percentile
An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | newlib | < newlib 4.4.0.20231231-2 (forky) | newlib 4.4.0.20231231-2 (forky) |
| newlib_project | newlib | — | — |
| newlib_project | newlib | >= 0 < 4.4.0.20231231-2 | 4.4.0.20231231-2 |
| newlib_project | newlib | >= 0 < 4.4.0.20231231-2 | 4.4.0.20231231-2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
newlib: arbitrary code execution via the time unit scaling in the _gettimeofday function
vendor_redhat·2024-08-20·CVSS 9.8
CVE-2024-30949 [CRITICAL] newlib: arbitrary code execution via the time unit scaling in the _gettimeofday function
newlib: arbitrary code execution via the time unit scaling in the _gettimeofday function
An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.
Statement: The package newlib is not shipped within any supported Red Hat product.
Debian
CVE-2024-30949: newlib - An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the ...
vendor_debian·2024·CVSS 9.8
CVE-2024-30949 [CRITICAL] CVE-2024-30949: newlib - An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the ...
An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 4.4.0.20231231-2)
sid: resolved (fixed in 4.4.0.20231231-2)
trixie: resolved (fixed in 4.4.0.20231231-2)
OSV
CVE-2024-30949: An issue in newlib v
osv·2024-08-20·CVSS 9.8
CVE-2024-30949 [CRITICAL] CVE-2024-30949: An issue in newlib v
An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.
GHSA
GHSA-qhpg-jf9r-mqxq: An issue in newlib v
ghsa_unreviewed·2024-08-20
CVE-2024-30949 [CRITICAL] CWE-190 GHSA-qhpg-jf9r-mqxq: An issue in newlib v
An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-20
Published