CVE-2024-43700

HIGH EPSS 17.1%
Published Aug 29, 20241y ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Aug 29, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow vulnerability. When a user of the affected product is tricked to process a specially crafted file, arbitrary code may be executed on the user's environment.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
17.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 2

CWE-120
CWE-787 Out-of-bounds Write Memory Safety

Affected Products 1

VendorProductVersionRange
philiphazelxfpt* <1.01

References 4

  • github.com https://github.com/PhilipHazel/xfpt
    Product
  • github.com https://github.com/PhilipHazel/xfpt/commit/a690304bbd3fd19e9dfdad50dcc87ad829f744e4
    Patch
  • jvn.jp https://jvn.jp/en/vu/JVNVU96498690/
    Third Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2024/11/msg00034.html

Remediation

  • github.com https://github.com/PhilipHazel/xfpt/commit/a690304bbd3fd19e9dfdad50dcc87ad829f744e4
    Patch