Severity
8.4HIGH
EPSS
0.1%
top 75.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 14
Latest updateJun 28

Description

Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.5 | Impact: 5.9

Affected Packages1 packages

NVDgnu/libcdio2.2.02.3.0

🔴Vulnerability Details

3
OSV
CVE-2024-36600: Buffer Overflow Vulnerability in libcdio 22024-06-14
GHSA
GHSA-89w5-xc64-fw9r: Buffer Overflow Vulnerability in libcdio v22024-06-14
CVEList
CVE-2024-36600: Buffer Overflow Vulnerability in libcdio 22024-06-14

📋Vendor Advisories

3
Ubuntu
libcdio vulnerability2024-06-28
Red Hat
libcdio: crafted iso image file leads to arbitrary code execution2024-06-14
Debian
CVE-2024-36600: libcdio - Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attack...2024