First published: Sun Nov 14 2021(Updated: )
An Out-of-bounds Read vulnerability exists in Open Design Alliance ODA Viewer before 2022.8. Crafted data in a DWF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opendesign Oda Viewer | <2022.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-43276 is high with a CVSS score of 7.8.
The affected software for CVE-2021-43276 is Open Design Alliance ODA Viewer before version 2022.8.
CVE-2021-43276 occurs due to an out-of-bounds read vulnerability in Open Design Alliance ODA Viewer.
An attacker can exploit CVE-2021-43276 by crafting data in a DWF file to trigger a read past the end of an allocated buffer.
Yes, the fix for CVE-2021-43276 is to update to version 2022.8 or later of Open Design Alliance ODA Viewer.