CVE-2024-52065

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-Windows (Persistence Service) allows Buffer Overflow via Environment Variables.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.1.2 before 6.1.2.21, from 5.3.1.40 before 5.3.1.41.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
cpe:2.3:a:rti:connext_professional:5.3.1.40:*:*:*:*:*:*:*

History

02 Oct 2025, 13:50

Type Values Removed Values Added
CPE cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
cpe:2.3:a:rti:connext_professional:5.3.1.40:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
CWE CWE-787
First Time Rti
Rti connext Professional
Summary
  • (es) La vulnerabilidad de copia de búfer sin comprobar el tamaño de la entrada ('desbordamiento de búfer clásico') en RTI Connext Professional en sistemas que no son Windows (servicio de persistencia) permite un desbordamiento de búfer a través de variables de entorno. Este problema afecta a Connext Professional: desde la versión 7.0.0 hasta la 7.3.0.2, desde la versión 6.1.1.2 hasta la 6.1.2.21, desde la versión 5.3.1.40 hasta la 5.3.1.41.
References () https://www.rti.com/vulnerabilities/#cve-2024-52065 - () https://www.rti.com/vulnerabilities/#cve-2024-52065 - Vendor Advisory

13 Dec 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-13 11:15

Updated : 2025-10-02 13:50


NVD link : CVE-2024-52065

Mitre link : CVE-2024-52065

CVE.ORG link : CVE-2024-52065


JSON object : View

Products Affected

rti

  • connext_professional
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CWE-787

Out-of-bounds Write