{"id":"CVE-2024-48075","details":"A Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL from 09/09/24 and earlier allows a remote attacker to trigger a Denial-of-Service via a malformed TLS Client Key Exchange message.","modified":"2026-08-12T14:52:17.487094Z","published":"2024-11-12T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/48xxx/CVE-2024-48075.json"},"references":[{"type":"WEB","url":"https://www.telekom.com/resource/blob/1083076/8bf5c03520005b8e699dfb9bce470fc7/dl-241104-cve-2024-48075-data.pdf"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/48xxx/CVE-2024-48075.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-48075"},{"type":"FIX","url":"https://github.com/RealTimeLogic/SharkSSL/commit/7045f6f254060640ff77eef2027f108fcc20e2f2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/realtimelogic/sharkssl","events":[{"introduced":"0"},{"fixed":"7045f6f254060640ff77eef2027f108fcc20e2f2"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-48075.json","vanir_signatures_modified":"2026-08-12T14:52:17Z","vanir_signatures":[{"id":"CVE-2024-48075-26053188","signature_type":"Function","signature_version":"v1","source":"https://github.com/realtimelogic/sharkssl/commit/7045f6f254060640ff77eef2027f108fcc20e2f2","target":{"file":"src/SharkSSL.c","function":"registerclass"},"deprecated":false,"digest":{"function_hash":"116193305503772636673916818953474959206","length":4429}},{"deprecated":false,"digest":{"function_hash":"52588606717552594754350960731798784924","length":8981},"id":"CVE-2024-48075-83259e85","signature_type":"Function","signature_version":"v1","source":"https://github.com/realtimelogic/sharkssl/commit/7045f6f254060640ff77eef2027f108fcc20e2f2","target":{"file":"src/SharkSSL.c","function":"handleptrauth"}},{"id":"CVE-2024-48075-cd957411","signature_type":"Line","signature_version":"v1","source":"https://github.com/realtimelogic/sharkssl/commit/7045f6f254060640ff77eef2027f108fcc20e2f2","target":{"file":"src/SharkSSL.c"},"deprecated":false,"digest":{"line_hashes":["296383553456154227019804201007982696045","139558402534532404322075431506175794548","57243565003680671761225258895222600141","124328239768517688657460062501883496030","263077822661664730474083990502323313256","47418585029071527733331880509740951522","280915899864689282767928938327850371108","81857769488931520861334125977086995630","219930885227605519137682339246165832014","158956598792563712455775452587847608131","83194762082125372655139678522306670887","326141084118160352954792430288821377950","193590586275851735075943357431325309077","337380596445218799214882255252218917703","40758777183056723520896790404111525750","274270759000240239180116153072587772014","280915899864689282767928938327850371108"],"threshold":0.9}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}