An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631). The malformed request will contain an empty Origin header value and a malformed Referer header value. The Referer header value will trigger a stack based buffer overflow when the host value in the Referer header is processed and is greater than 64 bytes in length.
History

Wed, 25 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Title Authenticated stack based buffer overflow affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, and RICOH. Authenticated stack based buffer overflow affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, and Konica Minolta, Inc.
References

Wed, 25 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 25 Jun 2025 07:30:00 +0000

Type Values Removed Values Added
Description An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631). The malformed request will contain an empty Origin header value and a malformed Referer header value. The Referer header value will trigger a stack based buffer overflow when the host value in the Referer header is processed and is greater than 64 bytes in length.
Title Authenticated stack based buffer overflow affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, and RICOH.
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published: 2025-06-25T07:20:29.048Z

Updated: 2025-06-25T14:08:48.280Z

Reserved: 2024-11-04T17:19:18.808Z

Link: CVE-2024-51979

cve-icon Vulnrichment

Updated: 2025-06-25T12:29:56.858Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-25T08:15:31.590

Modified: 2025-06-26T18:58:14.280

Link: CVE-2024-51979

cve-icon Redhat

No data.