5.5

CVE-2024-6638

Integer Overflow Vulnerability Reading TDMS Files in LabVIEW

An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an infinite loop.  Successful exploitation requires an attacker to provide a user with a specially crafted TDMS file.  This vulnerability affects LabVIEW 2024 Q1 and prior versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ni ≫ Labview Version <= 2021
Ni ≫ Labview Version 2022 Update q1
Ni ≫ Labview Version 2022 Update q3
Ni ≫ Labview Version 2022 Update q3_patch1
Ni ≫ Labview Version 2022 Update q3_patch2
Ni ≫ Labview Version 2023 Update q1
Ni ≫ Labview Version 2023 Update q3
Ni ≫ Labview Version 2023 Update q3_patch1
Ni ≫ Labview Version 2023 Update q3_patch2
Ni ≫ Labview Version 2023 Update q3_patch3
Ni ≫ Labview Version 2023 Update q3_patch4
Ni ≫ Labview Version 2024 Update q1
Ni ≫ Labview Version 2024 Update q1_patch1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.053
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
security@ni.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/integer-overflow-vulnerability-reading-tdms-files-in-labview.html
Vendor Advisory