CVE-2021-29118: Esri ArcReader PMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published Aug 12, 2022
·Updated
An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.
Affected Software
1 affected component
Esri ArcReader<=10.8.1
Event History
Aug 12, 2022
CVE Published
via MITRE·06:40 PM
Data Sourced
via MITRE·06:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-29118.
2
What is the severity of CVE-2021-29118?
The severity of CVE-2021-29118 is medium with a severity score of 5.5.
3
Which software versions are affected by CVE-2021-29118?
Esri ArcReader versions up to and including 10.8.1 are affected by CVE-2021-29118.
4
How can an attacker exploit CVE-2021-29118?
An attacker can exploit CVE-2021-29118 by parsing a specially crafted file in Esri ArcReader, which can result in an out-of-bounds read vulnerability and information disclosure.
5
Is authentication required for an attacker to exploit CVE-2021-29118?
No, authentication is not required for an attacker to exploit CVE-2021-29118.