Stack-based buffer overflow in zlib-rs - CVE-2024-11249
Published: November 21, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when decompressing untrusted input. A remote unauthenticated attacker can pass a specially crafted file to the application, trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Fedora
rust-zlib-rs
rust-rustls
How to mitigate CVE-2024-11249
rust-zlib-rs - addressed in versions 0.4.0-1.el9, 0.4.0-1.el10_0, 0.4.0-1.fc40, 0.4.0-1.fc41, 0.4.0-1.fc42
rust-rustls - addressed in versions 0.23.17-1.el9, 0.23.17-1.el10_0, 0.23.17-1.fc40, 0.23.17-1.fc41, 0.23.17-1.fc42