CVE Vulnerabilities

CVE-2023-42524

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Sep 18, 2023 | Modified: Sep 22, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Client_security Withsecure 15 (including) 15 (including)
Elements_endpoint_protection Withsecure 17 (including) *
Email_and_server_security Withsecure 15 (including) 15 (including)
Server_security Withsecure 15 (including) 15 (including)

References