An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.
References
Configurations
History
21 Aug 2024, 15:48
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/visitorckw/6b26e599241ea80210ea136b28441661 - Patch | |
References | () https://inbox.sourceware.org/newlib/20231129035714.469943-1-visitorckw%40gmail.com/ - Mailing List, Patch | |
References | () https://sourceware.org/git/?p=newlib-cygwin.git%3Ba=commit%3Bh=5f15d7c5817b07a6b18cbab17342c95cb7b42be4 - Broken Link | |
Summary |
|
|
CPE | cpe:2.3:a:newlib_project:newlib:4.3.0:*:*:*:*:*:*:* | |
CWE | CWE-190 | |
First Time |
Newlib Project newlib
Newlib Project |
20 Aug 2024, 18:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-787 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
20 Aug 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-20 15:15
Updated : 2024-08-21 15:48
NVD link : CVE-2024-30949
Mitre link : CVE-2024-30949
CVE.ORG link : CVE-2024-30949
JSON object : View
Products Affected
newlib_project
- newlib