Integer overflow in Azure AMQP library for C - CVE-2024-21646
Published: April 1, 2024
Vulnerability identifier: #VU87934
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21646
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow. A remote user can pass specially crafted data to the application, trigger an integer overflow and execute arbitrary code on the target system.
Affected software
Azure AMQP library for C
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Public Cloud Module
openSUSE Leap
python3-uamqp-debuginfo
python3-uamqp
python-uamqp-debugsource
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Public Cloud Module
openSUSE Leap
python3-uamqp-debuginfo
python3-uamqp
python-uamqp-debugsource
How to mitigate CVE-2024-21646
Install updates from vendor's website.
Azure AMQP library for C - update to 2024-01-01
python3-uamqp-debuginfo - update to 1.5.3-150100.4.10.1
python3-uamqp - update to 1.5.3-150100.4.10.1
python-uamqp-debugsource - update to 1.5.3-150100.4.10.1
python3-uamqp-debuginfo - update to 1.5.3-150100.4.10.1
python3-uamqp - update to 1.5.3-150100.4.10.1
python-uamqp-debugsource - update to 1.5.3-150100.4.10.1