CVE-2024-36600
published 2024-06-14CVE-2024-36600: Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
PriorityP338high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.36%
28.9th percentile
Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libcdio | — | — |
| gnu | libcdio | >= 2.2.0 < 2.3.0 | 2.3.0 |
CVSS provenance
nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.4HIGH
vendor_debian8.4LOW
vendor_redhat8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libcdio vulnerability
vendor_ubuntu·2024-06-28
CVE-2024-36600 libcdio vulnerability
Title: libcdio vulnerability
Summary: libcdio could be made to crash or run programs as your login if it
opened a specially crafted file.
Mansour Gashasbi discovered that libcdio incorrectly handled certain
memory operations when parsing an ISO file, leading to a buffer overflow
vulnerability. An attacker could use this to cause a denial of service
or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libcdio: crafted iso image file leads to arbitrary code execution
vendor_redhat·2024-06-14·CVSS 8.4
CVE-2024-36600 [HIGH] CWE-120 libcdio: crafted iso image file leads to arbitrary code execution
libcdio: crafted iso image file leads to arbitrary code execution
Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
A buffer overflow vulnerability was found in libcdio development version, which allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: libcdio (Red Hat Enterprise Linux 10) - Not affected
Package: python-pycdio (Red Hat Enterprise Linux 10) - Not affected
Package: libcdio (Red Hat Enterprise Linux 6) -
Debian
CVE-2024-36600: libcdio - Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attack...
vendor_debian·2024·CVSS 8.4
CVE-2024-36600 [HIGH] CVE-2024-36600: libcdio - Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attack...
Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
Scope: local
bookworm: resolved
bullseye: resolved
forky: open
sid: open
trixie: open
OSV
CVE-2024-36600: Buffer Overflow Vulnerability in libcdio 2
osv·2024-06-14·CVSS 8.4
CVE-2024-36600 [HIGH] CVE-2024-36600: Buffer Overflow Vulnerability in libcdio 2
Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
GHSA
GHSA-89w5-xc64-fw9r: Buffer Overflow Vulnerability in libcdio v2
ghsa_unreviewed·2024-06-14
CVE-2024-36600 [HIGH] CWE-121 GHSA-89w5-xc64-fw9r: Buffer Overflow Vulnerability in libcdio v2
Buffer Overflow Vulnerability in libcdio v2.1.0 allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
Suricata
ET WEB_CLIENT Adobe Acrobat Reader FlateDecode Stream Predictor Exploit Attempt
suricata·2011-07-01
CVE-2009-3459 ET WEB_CLIENT Adobe Acrobat Reader FlateDecode Stream Predictor Exploit Attempt
ET WEB_CLIENT Adobe Acrobat Reader FlateDecode Stream Predictor Exploit Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Adobe Acrobat Reader FlateDecode Stream Predictor Exploit Attempt"; flow:established,to_client; file.data; content:"Colors 1073741838"; fast_pattern; pcre:"/]*\x2FPredictor[^>]*\x2FColors\x201073741838/smi"; reference:url,www.fortiguard.com/analysis/pdfanalysis.html; reference:bid,36600; reference:cve,2009-3459; classtype:attempted-user; sid:2013153; rev:4; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2011_07_01, cve CVE_2009_3459, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_09;)
No public exploits indexed.
No writeups or analysis indexed.
2024-06-14
Published