ZDI-23-134: Open Design Alliance (ODA) Drawing SDK DWG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Open Design Alliance (ODA) Drawing SDK. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-134?
The severity of ZDI-23-134 is classified as medium due to the potential for sensitive information disclosure.
How do I fix ZDI-23-134?
To fix ZDI-23-134, users should ensure they apply the latest security updates provided by Open Design Alliance for the Drawing SDK.
What is the impact of ZDI-23-134?
The impact of ZDI-23-134 may include unauthorized access to sensitive information if exploited by an attacker.
Who is affected by ZDI-23-134?
ZDI-23-134 affects installations of the Open Design Alliance Drawing SDK used by individuals and organizations.
Is user interaction required to exploit ZDI-23-134?
Yes, user interaction is required since the target must visit a malicious page or open a malicious file to exploit ZDI-23-134.