Vulnerability Description
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafted MESH message could result in memory corruption when non-default build configuration is used. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Nimble | < 1.8.0 |
Related Weaknesses (CWE)
References
- https://github.com/apache/mynewt-nimble/commit/4f75c0b3b466186beff40e8489870c6cePatch
- https://lists.apache.org/thread/z8m7jqh54xybf9kz8q2l3tz92zsj7tmzMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2024/11/26/2Mailing ListVendor Advisory
FAQ
What is CVE-2024-47248?
CVE-2024-47248 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafted MESH message could result in memory corruption when non-default build configur...
How severe is CVE-2024-47248?
CVE-2024-47248 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-47248?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Nimble.