First published: Thu Apr 20 2023(Updated: )
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Datakit CrossCadWare | <2023.1 | |
Datakit CrossCAD/Ware_x64 library | <2023.1 | 2023.1 |
Datakit recommends user upgrade to v2023.1 https://www.datakit.com/en/crosscad_ware.php or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-22321.
The affected software is Datakit CrossCadWare.
The severity of CVE-2023-22321 is medium with a severity value of 5.5.
An attacker can exploit this vulnerability by parsing a specially crafted SLDPRT file, causing an out-of-bounds read past the end of an allocated buffer in the Datakit CrossCadWare_x64.dll.
Ensure that you are using Datakit CrossCadWare version 2023.1 or above, as these versions have addressed the vulnerability.