buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2024-36600
Component Overview
Vulnerability Overview
Name
CVE-2024-36600
Source
NVD (
link
)
Debian (
link
)
Description
Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
CWEs
CWE-121
Published Date
Jun 14, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugzilla.redhat.com/show_bug.cgi?id=2292833
Third Party Advisory
https://github.com/gashasbi/My-Reports/tree/main/CVE-2024-36600
Exploit
https://github.com/libcdio/libcdio/pull/32
Issue Tracking
https://github.com/libcdio/libcdio/pull/46
Issue Tracking
https://github.com/gashasbi/My-Reports/tree/main/CVE-2024-36600
Exploit
Analysis
#
Affected Component
Analysis
libcdio
Exploitable
Vulnerability Ratings
#
8.4
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libcdio
buildroot
master
2.3.0
Not Affected
libcdio
yocto
kirkstone
2.1.0
Not Affected
libcdio
yocto
master
2.3.0
Not Affected
libcdio
yocto
scarthgap
2.1.0
Not Affected