CVE-2021-38402: Delta Electronics DOPSoft 2 Stack-Based Buffer Overflow
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could lead to a stack-based buffer overflow while trying to copy to a buffer during font string handling. An attacker could leverage this vulnerability to execute code in the context of the current process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronic DOPSoft 2to a version that resolves this vulnerability.Fixed in 2.00.07 and prior - Compensating control
Delta Electronics recommends switching to the replacement software when available (DOPSoft 2 is end-of-life and will not receive updates to mitigate these vulnerabilities).
Event History
Frequently Asked Questions
What is the vulnerability ID for Delta Electronic DOPSoft 2?
The vulnerability ID for Delta Electronic DOPSoft 2 is CVE-2021-38402.
What is the severity of CVE-2021-38402?
The severity of CVE-2021-38402 is high, with a severity value of 7.8.
What is the affected software for CVE-2021-38402?
The affected software for CVE-2021-38402 is Delta Electronic DOPSoft 2 (Version 2.00.07 and prior).
What is the impact of CVE-2021-38402?
CVE-2021-38402 could lead to a stack-based buffer overflow while handling specific project files, potentially allowing an attacker to execute arbitrary code.
Is there a fix for CVE-2021-38402?
Yes, it is recommended to update to version 2.00.08 or later of Delta Electronic DOPSoft 2 to fix the vulnerability.