First published: Fri Aug 12 2022(Updated: )
An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.
Credit: psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri ArcReader | <=10.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29112 is an out-of-bounds read vulnerability in Esri ArcReader 10.8.1 and earlier versions.
CVE-2021-29112 allows an unauthenticated attacker to induce an information disclosure issue in the context of the current user.
CVE-2021-29112 has a severity rating of medium with a CVSS score of 5.5.
Esri ArcReader 10.8.1 and earlier versions are affected by CVE-2021-29112.
Yes, a patch is available to address the vulnerability in Esri ArcReader. It is recommended to update to the latest version.