CVE-2021-43278: High severity opendesign drawings software development kit vulnerability
Published Nov 14, 2021
·Updated
An Out-of-bounds Read vulnerability exists in the OBJ file reading procedure in Open Design Alliance Drawings SDK before 2022.11. The lack of validating the input length can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
1 affected component
Opendesign Drawings Software Developemnt Kit<2022.11
Event History
Nov 14, 2021
CVE Published
via MITRE·08:52 PM
Data Sourced
via MITRE·08:52 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-43278?
The severity of CVE-2021-43278 is high.
2
What is the CWE for CVE-2021-43278?
The CWE for CVE-2021-43278 is 125.
3
How does CVE-2021-43278 impact Open Design Alliance Drawings SDK?
CVE-2021-43278 allows an attacker to execute code in the context of the software.
4
How can I fix CVE-2021-43278?
To fix CVE-2021-43278, it is recommended to update to Open Design Alliance Drawings SDK version 2022.11 or later.
5
Where can I find more information about CVE-2021-43278?
More information about CVE-2021-43278 can be found at: https://www.opendesign.com/security-advisories