CVE-2024-36600 is a high-severity buffer overflow vulnerability in libcdio version 2.2.0, affecting GNU libcdio, that allows for arbitrary code execution. An attacker can trigger this by providing a specially crafted ISO 9660 image file. The CVSS score of 8.4 indicates a high impact with complete confidentiality, integrity, and availability compromise, requiring local access but no user interaction. There is currently no public exploit code available, it is not listed on the KEV catalog, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, < 2.3.0CPE matchmatch criteria | cpe:2.3:a:gnu:libcdio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.