Debian Azure-Uamqp-Python vulnerabilities

4 known vulnerabilities affecting debian/azure-uamqp-python.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2024-25110CRITICALCVSS 9.8fixed in azure-uamqp-python 1.6.8-2 (forky)2024
CVE-2024-25110 [CRITICAL] CVE-2024-25110: azure-uamqp-python - The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get... The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to update the submodule with commit `30865c9c`. There are no known workaroun
debian
CVE-2024-21646CRITICALCVSS 9.8fixed in azure-uamqp-python 1.6.8-1 (forky)2024
CVE-2024-21646 [CRITICAL] CVE-2024-21646: azure-uamqp-python - Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is us... Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When clients using this library receive a crafted binary type data, an integer overflow or wraparound or memory safety issue can occur and may cause remote code execution. This vulnerability has been patched i
debian
CVE-2024-27099CRITICALCVSS 9.8fixed in azure-uamqp-python 1.6.8-2 (forky)2024
CVE-2024-27099 [CRITICAL] CVE-2024-27099: azure-uamqp-python - The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. Whe... The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.6.8-2) sid: resolved (f
debian
CVE-2024-29195MEDIUMCVSS 6.0fixed in azure-uamqp-python 1.6.9-2 (forky)2024
CVE-2024-29195 [MEDIUM] CVE-2024-29195: azure-uamqp-python - The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure C... The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocation or heap buffer overflow due to vulnerabilities in parameter checking mechanism, by exploiting
debian