First published: Tue Dec 26 2023(Updated: )
An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used by the Fat structure in a crafted DGN file leads to an out-of-bounds write. An attacker can leverage this vulnerability to execute code in the context of the current process.
Credit: 8a9629cb-c5e7-4d2a-a894-111e8039b7ea
Affected Software | Affected Version | How to fix |
---|---|---|
Opendesign PRC SDK | <2024.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5180 has a severity that can lead to potential code execution vulnerabilities.
To fix CVE-2023-5180, upgrade to Open Design Alliance Drawings SDK version 2024.12 or later.
CVE-2023-5180 is a vulnerability in Open Design Alliance Drawings SDK that allows for an out-of-bounds write due to a corrupted value in a crafted DGN file.
Yes, an attacker can exploit CVE-2023-5180 by using a specially crafted DGN file.
Versions of Open Design Alliance Drawings SDK prior to 2024.12 are affected by CVE-2023-5180.