DSA-2024-032: Security Update for Dell Digital Delivery for a Buffer Overflow Vulnerability
Resumen: Dell Digital Delivery remediation is available for a buffer overflow vulnerability that could be exploited by malicious users to compromise the affected system.
Este artículo se aplica a
Este artículo no se aplica a
Este artículo no está vinculado a ningún producto específico.
No se identifican todas las versiones del producto en este artículo.
Impacto
High
Detalles
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-0156 | Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation. |
7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-0156 | Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation. |
7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Corrección y productos afectados
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Release Date (MM/DDD/YYYY) | Link |
|---|---|---|---|---|---|
| CVE-2024-0156 | Dell Digital Delivery | Versions prior to 5.2.0.0 | Version 5.2.0.0 or later | 08/01/2024 | https://www.dell.com/support/kbdoc/en-us/000192053/how-to-download-and-install-dell-digital-delivery |
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Release Date (MM/DDD/YYYY) | Link |
|---|---|---|---|---|---|
| CVE-2024-0156 | Dell Digital Delivery | Versions prior to 5.2.0.0 | Version 5.2.0.0 or later | 08/01/2024 | https://www.dell.com/support/kbdoc/en-us/000192053/how-to-download-and-install-dell-digital-delivery |
Soluciones alternativas y mitigaciones
None
Historial de revisiones
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-03-01 | Initial Release |
| 2.0 | 2024-03-01 | Updated for enhanced presentation with no changes to content |
| 3.0 | 2024-08-20 | Updated Affected Products and Remediation section Updated CVE description to update version |
Reconocimientos
Dell Technologies would like to thank Yue Liu From TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue.
Información relacionada
Descargo de responsabilidad
Productos afectados
UtilitiesPropiedades del artículo
Número del artículo: 000222536
Tipo de artículo: Dell Security Advisory
Última modificación: 20 ago 2024
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.