CVE-2024-52060

Severity CVSS v4.0:
HIGH
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
13/12/2024
Last modified:
02/10/2025

Description

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routing Service, Recording Service, Queuing Service, Observability Collector Service, Cloud Discovery Service) allows Buffer Overflow via Environment Variables.This issue affects Connext Professional: from 7.0.0 before 7.3.0.5, from 6.1.0 before 6.1.2.21, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.1.45.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:* 5.3.0 (including) 5.3.1.45 (excluding)
cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.1.40 (excluding)
cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:* 6.1.0 (including) 6.1.2.21 (excluding)
cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:* 7.0.0 (including) 7.3.0.5 (excluding)


References to Advisories, Solutions, and Tools