CVE-2023-26495: Use After Free
Published Apr 10, 2023
·Updated
An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code.
Affected Software
1 affected component
Opendesign Drawings Sdk<2024.1
Event History
Apr 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-26495.
2
What is the severity of CVE-2023-26495?
The severity of CVE-2023-26495 is high with a severity value of 7.8.
3
What is the affected software of CVE-2023-26495?
The affected software of CVE-2023-26495 is Open Design Alliance Drawings SDK before 2024.1.
4
How can an attacker exploit CVE-2023-26495?
An attacker can exploit CVE-2023-26495 by crafting a malicious DWG file to force the SDK to reuse a freed object, allowing them to execute arbitrary code.
5
Is there a fix for CVE-2023-26495?
Yes, upgrading to Open Design Alliance Drawings SDK version 2024.1 or newer will fix CVE-2023-26495.