CVE-2024-13941
Last modified
CVE-2024-13941 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ouch::archive::zip::convert_zip_date_time of the file zip.rs. The manipulation of the argument month leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 0.4.0 is able to address this issue. It is recommended to upgrade the affected component.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-13941?
How severe is CVE-2024-13941?
How do I fix CVE-2024-13941?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-13930An Unchecked Loop Condition in ASPECT provides an attacker t…5.9
- CVE-2024-13931Relative Path Traversal vulnerabilities in ASPECT allow acce…7.5
- CVE-2024-13933The FoodBakery | Delivery Restaurant Directory WordPress The…8.8
- CVE-2024-13939String::Compare::ConstantTime for Perl through 0.321 is vuln…7.5
- CVE-2024-1394A memory leak flaw was found in Golang in the RSA encrypting…7.5
- CVE-2024-13940The Ninja Forms Webhooks plugin for WordPress is vulnerable …5.5
- CVE-2024-13943Tesla Model S Iris Modem QCMAP_ConnectionManager Improper In…7.8
- CVE-2024-13944Link Following Local Privilege Escalation Vulnerability in N…7.8
- CVE-2024-13945Stored Absolute Path Traversal vulnerabilities in ASPECT cou…8.4
- CVE-2024-13946DLL's are not digitally signed when loaded in ASPECT's confi…7.1
- CVE-2024-13947Device commissioning parameters in ASPECT may be modified by…7.1
- CVE-2024-13948Windows permissions for ASPECT configuration toolsets are no…7.3
Are you affected by CVE-2024-13941?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
