ZDI-23-133: Open Design Alliance (ODA) Drawing SDK DWG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published Feb 9, 2023
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Open Design Alliance (ODA) Drawing SDK. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Open Design Alliance Drawing SDK
Event History
Feb 9, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-133?
ZDI-23-133 is classified as a vulnerability that can lead to sensitive information disclosure.
2
How do I fix ZDI-23-133?
To mitigate ZDI-23-133, ensure that users do not open files or visit web pages from untrusted sources.
3
Who is affected by ZDI-23-133?
ZDI-23-133 affects installations of the Open Design Alliance Drawing SDK.
4
Is user interaction required to exploit ZDI-23-133?
Yes, user interaction is necessary as the target must visit a malicious page or open a malicious file.
5
What type of attack is related to ZDI-23-133?
ZDI-23-133 is related to remote information disclosure attacks.