Intel

AIKIDO-2024-10074

uamqp is vulnerable to Code Injection

Code InjectionCVE-2024-21646 Published May 2, 2024

95

Critical Risk

This Affects:

pythonuamqp
0.1.0 - 1.6.6
Fixed in 1.6.7
Are you affected? Scan for Free

TL;DR

Affected versions of the uamqp library are vulnerable to command injection when clients process manipulated binary data types. Attackers can exploit integer overflow or memory safety issues in the crafted data to execute arbitrary code on the targeted system.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

uamqp is vulnerable to Code Injection in versions 0.1.0 - 1.6.6.

How to fix this

Upgrade the uamqp library to the patch version.