CVE-2024-3203
Estado: AnalizadaCrítica (9.8)—
A vulnerability, which was classified as critical, was found in c-blosc2 up to 2.13.2. Affected is the function ndlz8_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz8x8.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.14.3 is able to address this issue. It is recommended to upgrade the affected component. VDB-259050 is the identifier assigned to this vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.35%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-122
Referencias
- https://drive.google.com/drive/folders/1T1k3UeS09m65LjVXExUuZfedNQPWQWCo?usp=sharing
- https://github.com/Blosc/c-blosc2/releases/tag/v2.14.3
- https://vuldb.com/?ctiid.259050
- https://vuldb.com/?id.259050
- https://vuldb.com/?submit.304556
- https://drive.google.com/drive/folders/1T1k3UeS09m65LjVXExUuZfedNQPWQWCo?usp=sharing
- https://github.com/Blosc/c-blosc2/releases/tag/v2.14.3
- https://vuldb.com/?ctiid.259050
- https://vuldb.com/?id.259050
- https://vuldb.com/?submit.304556
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-3203",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-3203",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-04-03T15:02:29.729304Z"
}
}
],
"cvssMetricV2": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.3,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cna@vuldb.com",
"affectedData": [
{
"vendor": "n/a",
"product": "c-blosc2",
"versions": [
{
"status": "affected",
"version": "2.13.0"
},
{
"status": "affected",
"version": "2.13.1"
},
{
"status": "affected",
"version": "2.13.2"
}
]
}
]
}
],
"published": "2024-04-02T22:15:10.320",
"references": [
{
"url": "https://drive.google.com/drive/folders/1T1k3UeS09m65LjVXExUuZfedNQPWQWCo?usp=sharing",
"tags": [
"Product"
],
"source": "cna@vuldb.com"
},
{
"url": "https://github.com/Blosc/c-blosc2/releases/tag/v2.14.3",
"tags": [
"Release Notes"
],
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.259050",
"tags": [
"Permissions Required",
"VDB Entry"
],
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.259050",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?submit.304556",
"tags": [
"Exploit",
"VDB Entry"
],
"source": "cna@vuldb.com"
},
{
"url": "https://drive.google.com/drive/folders/1T1k3UeS09m65LjVXExUuZfedNQPWQWCo?usp=sharing",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/Blosc/c-blosc2/releases/tag/v2.14.3",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://vuldb.com/?ctiid.259050",
"tags": [
"Permissions Required",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://vuldb.com/?id.259050",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://vuldb.com/?submit.304556",
"tags": [
"Exploit",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"description": [
{
"lang": "en",
"value": "CWE-122"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability, which was classified as critical, was found in c-blosc2 up to 2.13.2. Affected is the function ndlz8_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz8x8.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.14.3 is able to address this issue. It is recommended to upgrade the affected component. VDB-259050 is the identifier assigned to this vulnerability."
},
{
"lang": "es",
"value": "Una vulnerabilidad fue encontrada en c-blosc2 hasta 2.13.2 y clasificada como crítica. La función ndlz8_decompress del archivo /src/c-blosc2/plugins/codecs/ndlz/ndlz8x8.c es afectada por la vulnerabilidad. La manipulación conduce a un desbordamiento de búfer de almacenamiento dinámico. Es posible lanzar el ataque de forma remota. El exploit ha sido divulgado al público y puede utilizarse. VDB-259050 es el identificador asignado a esta vulnerabilidad. NOTA: Se contactó primeramente al proveedor sobre esta divulgación, pero no respondió de ninguna manera."
}
],
"lastModified": "2026-06-17T07:43:31.673",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:blosc:c-blosc2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3560FC02-24C1-498F-AA85-9EEF17F86841",
"versionEndIncluding": "2.13.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@vuldb.com"
}