CVE-2024-43167
Last modified
CVE-2024-43167 is a low-severity vulnerability rated 2.8/10 on the CVSS scale. DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. NLnet Labs has no further information about the claim, and suggests that affected Red Hat customers refer to available Red Hat documentation or support channels. ORIGINAL DESCRIPTION: A NULL pointer dereference flaw was found in the ub_ctx_set_fwd function in Unbound. This issue could allow an attacker who can invoke specific sequences of API calls to cause a segmentation fault. When certain API functions such as ub_ctx_set_fwd and ub_ctx_resolvconf are called in a particular order, the program attempts to read from a NULL pointer, leading to a crash. This issue can result in a denial of service by causing the application to terminate unexpectedly.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-43167?
How severe is CVE-2024-43167?
How do I fix CVE-2024-43167?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-43161Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2024-43162Missing Authorization vulnerability in Easy Digital Download…8.8
- CVE-2024-43163Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2024-43164Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-43165Improper Limitation of a Pathname to a Restricted Directory …6.5
- CVE-2024-43166Incorrect Default Permissions vulnerability in Apache Dolphi…9.8
- CVE-2024-43168DISPUTE NOTE: this issue does not pose a security risk as it…4.8
- CVE-2024-43169IBM Engineering Requirements Management DOORS Next 7.0.2, 7.…6.5
- CVE-2024-4317Missing authorization in PostgreSQL built-in views pg_stats_…4.3
- CVE-2024-43173IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely …3.7
- CVE-2024-43176IBM OpenPages 9.0 could allow an authenticated user to obtai…5.4
- CVE-2024-43177IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely …9.8
Are you affected by CVE-2024-43167?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
