CVE Vulnerabilities

CVE-2024-0316

Improper Cleanup on Thrown Exception

Published: Jan 15, 2024 | Modified: Jan 19, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple request packets to the containment_notify/preview parameter, which could lead to a service outage.

Weakness

The product does not clean up its state or incorrectly cleans up its state when an exception is thrown, leading to unexpected state or control flow.

Affected Software

Name Vendor Start Version End Version
Endpoint_security Fireeye 5.2.0.958244 (including) 5.2.0.958244 (including)

Potential Mitigations

References