First published: Sun Nov 14 2021(Updated: )
An out-of-bounds read vulnerability exists in the U3D file reading procedure in Open Design Alliance PRC SDK before 2022.10. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opendesign Oda Prc Software Development Kit | <2022.10 | |
<2022.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43277 is an out-of-bounds read vulnerability in the U3D file reading procedure in Open Design Alliance PRC SDK before 2022.10.
CVE-2021-43277 can be exploited by a crafted U3D file to trigger a read past the end of an allocated buffer, potentially leading to arbitrary code execution.
CVE-2021-43277 has a severity score of 7.8 (high).
To fix CVE-2021-43277, update Open Design Alliance PRC SDK to version 2022.10 or higher.
You can find more information about CVE-2021-43277 in the Open Design Alliance security advisories: [link](https://www.opendesign.com/security-advisories).