Back to Database
Status published
Medium
CVE-2024-10933
OpenBSD readdir directory traversal
Vulnerability Description
In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10933
Credits & Attribution
No credits recorded in the NVD database.
References
More from OpenBSD
View All →CVE-2025-61985
ssh in OpenSSH before 10.1 allows the '\0' character in...
Low
3.6
CVE-2025-61984
ssh in OpenSSH before 10.1 allows control characters in usernames...
Low
3.6
CVE-2025-32728
In sshd in OpenSSH before 10.0, the DisableForwarding directive does...
Medium
4.3
CVE-2025-30334
OpenBSD wg(4) kernel crash
High
7.1
CVE-2024-11149
OpenBSD vmm GDTR limits
Medium
6.2
Affected Vendor
OpenBSD
View all reports →Affected Software
OpenBSD
Vulnerable Versions:
7.5, 7.4, 7.5 errata 009, 7.4 errata 022
Timeline
Official Publish:
December 5th, 2024
Last Modified:
December 5th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N