GHSA-4qhr-qf46-fcrx: Buffer Overflow
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-63gh-g2x5-x69v. This link is maintained to preserve external references.
Original Description Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Microsoft.DiaSymReader.Nativeto a version that resolves this vulnerability.Fixed in 18.9.0-beta1.26405.2
Event History
Frequently Asked Questions
Should this advisory be used for remediation tracking?
No. It was withdrawn as a duplicate of GHSA-63gh-g2x5-x69v, which is the advisory to use for current vulnerability and remediation information.
What impact was originally reported?
The original report described a heap-based buffer overflow in Visual Studio that could allow an unauthorized attacker to execute code over a network. The listed impact includes high confidentiality, integrity, and availability effects.