CVE-2024-43168
CVE-2024-43168 is a reported heap-buffer-overflow in Unbound's config_file.c that may lead to memory corruption. While disputed by the original developer (NLnet Labs) who considers it within expected functionality, Red Hat claims a security risk in their products. The vulnerability lies in the cfg_mark_ports function and could potentially be exploited by an attacker with local access using specially crafted input. If exploitable, this could cause the application to crash or, in the worst case, allow for arbitrary code execution leading to a denial of service. The SOCRadar Vulnerability Risk Score (SVRS) for CVE-2024-43168 is 30, indicating a lower level of immediate risk, but requires monitoring, especially if using affected Red Hat products. Although tagged 'In The Wild', the dispute over its exploitability suggests caution when prioritizing patching, emphasizing the need to evaluate based on your specific environment.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.