yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-52949
Component Overview
Vulnerability Overview
Name
CVE-2024-52949
Source
NVD (
link
)
Debian (
link
)
Description
iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control the size, and it is consequently possible to overflow memory on the stack.
CWEs
CWE-120
Published Date
Dec 16, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/iptraf-ng/iptraf-ng/releases/tag/v1.2.1
Release Notes
https://www.gruppotim.it/it/footer/red-team.html
Exploit
https://www.gruppotim.it/it/footer/red-team.html
Exploit
Analysis
#
Affected Component
Analysis
iptraf-ng
Patched
Vulnerability Ratings
#
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
iptraf-ng
yocto
master
1.2.2
Not Affected
iptraf-ng
yocto
scarthgap
1.2.1
Patched
Resolved with patches
#
iptraf-ng (yocto:kirkstone)
#
Title
Author
Resolve
1
interface names: limit length to IFNAMSIZ
Vitezslav Samel <vitezslav@samel.cz>
CVE-2024-52949
iptraf-ng (yocto:scarthgap)
#
Title
Author
Resolve
1
interface names: limit length to IFNAMSIZ
Vitezslav Samel <vitezslav@samel.cz>
CVE-2024-52949