
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A Buffer Overflow vulnerability was identified in libcdio v2.1.0, tracked as CVE-2024-36600. The vulnerability allows attackers to execute arbitrary code through a specially crafted ISO 9660 image file. The issue was discovered in May 2024 by Mansour Gashasbi and affects the GNU Compact Disc Input and Control library (libcdio), which provides functionality for CD-ROM and CD image access (GitHub Report).
The vulnerability stems from improper buffer allocation for UTF-8 filename strings. The buffer is allocated with the same length as the UCS-2 string, but this becomes problematic when handling glyphs that use 3 or 4-byte UTF-8 sequences. Since a single character in the filename may require multiple bytes in UTF-8 representation, the total bytes needed could exceed the allocated buffer size, even when the character count matches the UCS-2 string length. The vulnerability was introduced in the development version after commit 4c840665 (GitHub Report).
Successful exploitation of this vulnerability could allow attackers to execute arbitrary code on the affected system through a specially crafted ISO 9660 image file (NVD).
Several Linux distributions have released fixes for this vulnerability. Debian has addressed the issue across multiple releases: bullseye (2.1.0-2), bookworm (2.1.0-4), trixie (2.1.0-5), and sid (2.2.0-1). Ubuntu has also released security updates through USN-6855-1 (Debian Tracker, Rapid7).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”