CVE-2021-29112: Esri ArcReader PMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published Aug 12, 2022
·Updated
An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.
Affected Software
1 affected component
Esri ArcReader<=10.8.1
Event History
Aug 12, 2022
CVE Published
via MITRE·06:40 PM
Data Sourced
via MITRE·06:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-29112?
CVE-2021-29112 is an out-of-bounds read vulnerability in Esri ArcReader 10.8.1 and earlier versions.
2
How does CVE-2021-29112 impact Esri ArcReader?
CVE-2021-29112 allows an unauthenticated attacker to induce an information disclosure issue in the context of the current user.
3
What is the severity of CVE-2021-29112?
CVE-2021-29112 has a severity rating of medium with a CVSS score of 5.5.
4
Which version of Esri ArcReader is affected by CVE-2021-29112?
Esri ArcReader 10.8.1 and earlier versions are affected by CVE-2021-29112.
5
Is there a patch available for CVE-2021-29112?
Yes, a patch is available to address the vulnerability in Esri ArcReader. It is recommended to update to the latest version.