Vulnerability Description
In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openbsd | < 7.4 |
Related Weaknesses (CWE)
References
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.4/common/022_readdir.patch.sigPatch
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.5/common/009_readdir.patch.sigPatch
FAQ
What is CVE-2024-10933?
CVE-2024-10933 is a vulnerability with a CVSS score of 5.0 (MEDIUM). In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.
How severe is CVE-2024-10933?
CVE-2024-10933 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-10933?
Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openbsd.