CVE-2021-44044: High severity opendesign prc sdk vulnerability
An out-of-bounds write vulnerability exists when reading a JPG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists with parsing JPG files. Crafted data in a JPG (4 extraneous bytes before the marker 0xca) can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44044?
CVE-2021-44044 is an out-of-bounds write vulnerability that exists when reading a JPG file using Open Design Alliance Drawings SDK before version 2022.11.
What is the severity of CVE-2021-44044?
CVE-2021-44044 has a high severity rating of 7.8 out of 10.
How does CVE-2021-44044 work?
CVE-2021-44044 occurs when parsed JPG files contain crafted data that triggers a write operation beyond the allocated buffer.
Which software is affected by CVE-2021-44044?
Open Design Alliance Drawings SDK versions up to and excluding 2022.11 are affected by CVE-2021-44044.
How can I fix CVE-2021-44044?
To fix CVE-2021-44044, it is recommended to update to version 2022.11 or later of Open Design Alliance Drawings SDK.