Vulnerability Description
GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When params.n_tries is negative, incorrect memory allocation occurs.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Gnu Scientific Library | <= 2.8 |
Related Weaknesses (CWE)
References
- https://git.savannah.gnu.org/cgit/gsl.git/log/siman/siman.cProduct
- https://github.com/silviadefra/GolDRuSh/blob/main/vulnerabilities/gsl.mdExploitThird Party Advisory
- https://www.gnu.org/software/gsl/doc/html/siman.htmlProduct
FAQ
What is CVE-2024-50610?
CVE-2024-50610 is a vulnerability with a CVSS score of 3.6 (LOW). GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When params.n_tries is negative, incorrect memory allocation occurs.
How severe is CVE-2024-50610?
CVE-2024-50610 has been rated LOW with a CVSS base score of 3.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-50610?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Gnu Scientific Library.