GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When params.n_tries is negative, incorrect memory allocation occurs.
References
Link | Resource |
---|---|
https://git.savannah.gnu.org/cgit/gsl.git/log/siman/siman.c | Product |
https://github.com/silviadefra/GolDRuSh/blob/main/vulnerabilities/gsl.md | Exploit Third Party Advisory |
https://www.gnu.org/software/gsl/doc/html/siman.html | Product |
Configurations
History
04 Sep 2025, 16:43
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:gnu:gnu_scientific_library:*:*:*:*:*:*:*:* | |
First Time |
Gnu gnu Scientific Library
Gnu |
|
References | () https://git.savannah.gnu.org/cgit/gsl.git/log/siman/siman.c - Product | |
References | () https://github.com/silviadefra/GolDRuSh/blob/main/vulnerabilities/gsl.md - Exploit, Third Party Advisory | |
References | () https://www.gnu.org/software/gsl/doc/html/siman.html - Product |
30 Oct 2024, 19:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.6 |
CWE | CWE-190 |
28 Oct 2024, 13:58
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
27 Oct 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-27 22:15
Updated : 2025-09-04 16:43
NVD link : CVE-2024-50610
Mitre link : CVE-2024-50610
CVE.ORG link : CVE-2024-50610
JSON object : View
Products Affected
gnu
- gnu_scientific_library
CWE
CWE-190
Integer Overflow or Wraparound