CVE-2021-21830: Buffer Overflow
Published Aug 13, 2021
·Updated
A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
1 affected component
Att Xmill=0.7
Event History
Aug 13, 2021
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-21830?
CVE-2021-21830 is a heap-based buffer overflow vulnerability in the XML Decompression function of AT&T Labs’ Xmill 0.7.
2
How severe is CVE-2021-21830?
CVE-2021-21830 has a severity rating of 9.8, which is considered critical.
3
What is the affected software?
The affected software is AT&T Labs’ Xmill 0.7.
4
How does CVE-2021-21830 work?
CVE-2021-21830 can be triggered by providing a specially crafted XMI file, which can lead to remote code execution.
5
Is there a fix for CVE-2021-21830?
There is currently no fix available for CVE-2021-21830.