CVE-2024-24259

freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:artifex:mupdf:1.23.9:*:*:*:*:*:*:*

History

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://github.com/freeglut/freeglut/pull/155 - () https://github.com/freeglut/freeglut/pull/155 -
References () https://github.com/yinluming13579/mupdf_defects/blob/main/mupdf_detect_2.md - Exploit, Third Party Advisory () https://github.com/yinluming13579/mupdf_defects/blob/main/mupdf_detect_2.md - Exploit, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IBAWX3HMMZVAWJZ3U6VOAYYOYJCN3IS/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IBAWX3HMMZVAWJZ3U6VOAYYOYJCN3IS/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T43DAHPIWMGN54E4I6ABLHNYHZSTX7H5/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T43DAHPIWMGN54E4I6ABLHNYHZSTX7H5/ -

21 Feb 2024, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IBAWX3HMMZVAWJZ3U6VOAYYOYJCN3IS/ -

20 Feb 2024, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T43DAHPIWMGN54E4I6ABLHNYHZSTX7H5/ -

12 Feb 2024, 17:15

Type Values Removed Values Added
References
  • () https://github.com/freeglut/freeglut/pull/155 -
Summary mupdf v1.23.9 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function. freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.

07 Feb 2024, 23:01

Type Values Removed Values Added
CWE CWE-401
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://github.com/yinluming13579/mupdf_defects/blob/main/mupdf_detect_2.md - () https://github.com/yinluming13579/mupdf_defects/blob/main/mupdf_detect_2.md - Exploit, Third Party Advisory
First Time Artifex
Artifex mupdf
CPE cpe:2.3:a:artifex:mupdf:1.23.9:*:*:*:*:*:*:*

05 Feb 2024, 18:25

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-05 18:15

Updated : 2024-11-21 08:59


NVD link : CVE-2024-24259

Mitre link : CVE-2024-24259

CVE.ORG link : CVE-2024-24259


JSON object : View

Products Affected

artifex

  • mupdf
CWE
CWE-401

Missing Release of Memory after Effective Lifetime