CVE-2024-54662
CVE-2024-54662
9.1
CriticalPublished:
Last updated:
Source:cve@mitre.org
Deferred
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- None
Description
Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod.
References
cve@mitre.org
https://www.inet.no/dante/cve@mitre.org
https://www.inet.no/dante/advisory-2024-12-16.txt