ZDI-23-867: (0Day) Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Jun 15, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Ashlar-Vellum Graphite
Event History
Jun 15, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:07 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-867?
The severity of ZDI-23-867 is classified as high due to the potential for remote code execution.
2
How do I fix ZDI-23-867?
To fix ZDI-23-867, update to the latest version of Ashlar-Vellum Graphite that addresses this vulnerability.
3
What type of attacks are possible with ZDI-23-867?
ZDI-23-867 allows remote attackers to execute arbitrary code through user interaction with a malicious page or file.
4
Is user interaction required to exploit ZDI-23-867?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file.
5
What products are affected by ZDI-23-867?
ZDI-23-867 affects installations of Ashlar-Vellum Graphite.