First published: Sun Dec 05 2021(Updated: )
A use-after-free vulnerability exists when reading a DWF/DWFX file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists with parsing DWF/DWFX files. Crafted data in a DWF/DWFX file and lack of proper validation of input data can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opendesign Drawings Sdk | <2022.11 | |
<2022.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44047 is a use-after-free vulnerability that exists when reading a DWF/DWFX file using Open Design Alliance Drawings SDK before 2022.11.
CVE-2021-44047 occurs due to a use-after-free issue with parsing DWF/DWFX files, which can be triggered by crafted data in a DWF/DWFX file and lack of proper validation of input data.
CVE-2021-44047 has a severity score of 7.8 (high).
CVE-2021-44047 affects Open Design Alliance Drawings SDK before version 2022.11.
To fix CVE-2021-44047, you should update to Open Design Alliance Drawings SDK version 2022.11 or newer.