CVE-2021-44859: High severity opendesign drawings software development kit vulnerability
An out-of-bounds read vulnerability exists when reading a TGA file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TGA files. An unchecked input data from a crafted TGA file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44859?
CVE-2021-44859 is an out-of-bounds read vulnerability that exists when reading a TGA file using Open Design Alliance Drawings SDK before version 2022.12.
How does CVE-2021-44859 impact Open Design Alliance Drawings SDK?
CVE-2021-44859 allows an attacker to exploit the vulnerability by providing a crafted TGA file, leading to an out-of-bounds read and potentially enabling further attacks.
What is the severity of CVE-2021-44859?
CVE-2021-44859 has a severity rating of 7.8, which is considered high.
How can I mitigate CVE-2021-44859?
To mitigate CVE-2021-44859, it is recommended to update to Open Design Alliance Drawings SDK version 2022.12 or newer.
Where can I find more information about CVE-2021-44859?
More information about CVE-2021-44859 can be found at the Open Design Alliance security advisories page: https://www.opendesign.com/security-advisories