CVE-2024-21646
When clients using this library receive a crafted binary type data, an integer overflow or wraparound or memory safety issue can occur and may cause remote code execution.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When clients using this library receive a crafted binary type data, an integer overflow or wraparound or memory safety issue can occur and may cause remote code execution. This vulnerability has been patched in release 2024-01-01.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.11% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94, CWE-190
- Affected
- microsoft/azure uamqp
- Source
- security-advisories@github.com
References
- https://github.com/Azure/azure-uamqp-c/commit/12ddb3a31a5a97f55b06fa5d74c59a1d84ad78fePatch
- https://github.com/Azure/azure-uamqp-c/security/advisories/GHSA-j29m-p99g-7hpvVendor Advisory
- https://github.com/Azure/azure-uamqp-c/commit/12ddb3a31a5a97f55b06fa5d74c59a1d84ad78fePatch
- https://github.com/Azure/azure-uamqp-c/security/advisories/GHSA-j29m-p99g-7hpvVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.