Use-after-free in Azure AMQP library for C - CVE-2024-25110

 

Use-after-free in Azure AMQP library for C - CVE-2024-25110

Published: April 1, 2024


Vulnerability identifier: #VU87933
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-25110
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the open_get_offered_capabilities() function. A remote attacker can trigger a use-after-free error and execute arbitrary code on the system.


Affected software

Azure AMQP library for C
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Public Cloud Module
openSUSE Leap
python-uamqp-debugsource
python3-uamqp-debuginfo
python3-uamqp

How to mitigate CVE-2024-25110

Install updates from vendor's website.

Azure AMQP library for C - update to 2024-01-01
python-uamqp-debugsource - update to 1.5.3-150100.4.13.1
python3-uamqp-debuginfo - update to 1.5.3-150100.4.13.1
python3-uamqp - update to 1.5.3-150100.4.13.1

External References

Related Security Bulletins