The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to update the submodule with commit `30865c9c`. There are no known workarounds for this vulnerability.

Subscriptions

Vendors Products
Microsoft Subscribe
Azure Uamqp Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-22471 The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to update the submodule with commit `30865c9c`. There are no known workarounds for this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 22 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft azure Uamqp
CPEs cpe:2.3:a:azure:uamqp:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_uamqp:*:*:*:*:*:c:*:*
Vendors & Products Azure
Azure uamqp
Microsoft
Microsoft azure Uamqp

Thu, 07 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Oct 2024 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Azure
Azure uamqp
Weaknesses CWE-416
CPEs cpe:2.3:a:azure:uamqp:*:*:*:*:*:*:*:*
Vendors & Products Azure
Azure uamqp

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-11-07T19:12:40.403Z

Reserved: 2024-02-05T14:14:46.378Z

Link: CVE-2024-25110

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:21.641Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-12T20:15:08.803

Modified: 2024-11-22T14:48:36.047

Link: CVE-2024-25110

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-02-10T00:00:00Z

Links: CVE-2024-25110 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses