Intel

AIKIDO-2024-10204

EVerest.everest-core is vulnerable to Integer Overflow

Integer OverflowCVE-2024-37310 Published Aug 5, 2024

91

Critical Risk

This Affects:

c++EVerest.everest-core
2022.11.0 - 2024.3.0
Fixed in 2024.3.1
2024.4.0 - 2024.5.0
Fixed in 2024.6.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to integer overflow. An integer overflow in the v2g_incoming_v2gtp function in the v2g_server.cpp implementation allows a remote attacker to overflow the process's heap.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

EVerest.everest-core is vulnerable to Integer Overflow in versions 2024.4.0 - 2024.5.0 and 2022.11.0 - 2024.3.0.

How to fix this

Upgrade the EVerest.everest-core library to the patch version.