DSA-2024-032: Security Update for Dell Digital Delivery for a Buffer Overflow Vulnerability
Zhrnutie: Dell Digital Delivery remediation is available for a buffer overflow vulnerability that could be exploited by malicious users to compromise the affected system.
Tento článok sa vzťahuje na
Tento článok sa nevzťahuje na
Tento článok nie je viazaný na žiadny konkrétny produkt.
V tomto článku nie sú uvedené všetky verzie produktov.
Dosah
High
Podrobnosti
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-0156 | Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation. |
7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-0156 | Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation. |
7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Dotknuté produkty a riešenie problému
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Release Date (MM/DDD/YYYY) | Link |
|---|---|---|---|---|---|
| CVE-2024-0156 | Dell Digital Delivery | Versions prior to 5.2.0.0 | Version 5.2.0.0 or later | 08/01/2024 | https://www.dell.com/support/kbdoc/en-us/000192053/how-to-download-and-install-dell-digital-delivery |
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Release Date (MM/DDD/YYYY) | Link |
|---|---|---|---|---|---|
| CVE-2024-0156 | Dell Digital Delivery | Versions prior to 5.2.0.0 | Version 5.2.0.0 or later | 08/01/2024 | https://www.dell.com/support/kbdoc/en-us/000192053/how-to-download-and-install-dell-digital-delivery |
Alternatívne riešenia a zmiernenia
None
História revízií
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-03-01 | Initial Release |
| 2.0 | 2024-03-01 | Updated for enhanced presentation with no changes to content |
| 3.0 | 2024-08-20 | Updated Affected Products and Remediation section Updated CVE description to update version |
Potvrdenia
Dell Technologies would like to thank Yue Liu From TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue.
Súvisiace informácie
Legal Disclaimer
Dotknuté produkty
UtilitiesVlastnosti článku
Číslo článku: 000222536
Typ článku: Dell Security Advisory
Dátum poslednej úpravy: 20 aug 2024
Nájdite odpovede na svoje otázky od ostatných používateľov spoločnosti Dell
Služby podpory
Skontrolujte, či sa na vaše zariadenie vzťahujú služby podpory.