Back to Labs
Security Advisory

CVE-2024-34952

About

taurusxin ncmdump v1.3.2 was discovered to contain a segmentation violation via the NeteaseCrypt::FixMetadata() function at /src/ncmcrypt.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted .ncm file.

Weakness (CWE):CWE-476

Rainforest analyst review

ncmdump, a small command-line utility for converting .ncm files, dereferences a null pointer while fixing metadata, so a specially crafted file crashes it. That's the whole impact: a segmentation fault and a denial of service against a local tool. Nothing is disclosed, nothing is modified, and there's no privilege gain.

This sits at the bottom of the risk ladder for good reason. Exploiting it means getting a target to run the tool locally against a malicious file, and the payoff is merely that the tool stops. There's no persistence, no lateral movement, and no data at stake; it's a robustness bug in a niche converter, not a security event with downstream consequences.

We rank this near the floor of the batch and would not spend an emergency cycle on it. If ncmdump appears anywhere in our tooling or automated pipelines, the sensible move is simply to update it and avoid feeding it untrusted files, but it doesn't warrant exposure mapping or virtual patching. Its main value to us is as a reminder to keep an eye on the reliability of small third-party utilities embedded in workflows.

References

Related CVEs

Frequently asked questions

What is CVE-2024-34952?

taurusxin ncmdump v1.3.2 was discovered to contain a segmentation violation via the NeteaseCrypt::FixMetadata() function at /src/ncmcrypt.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted .ncm file.

How severe is CVE-2024-34952?

CVE-2024-34952 carries a CVSS 3.1 base score of 5, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 41 out of 100, in the moderate band.

How is CVE-2024-34952 exploited?

According to the CVSS vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H): attack vector Local, attack complexity Low, privileges required Low, user interaction Required. Impact on confidentiality None, integrity None and availability High.

How do I fix CVE-2024-34952?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email