ZDI-23-868: (0Day) Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Jun 15, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Ashlar-Vellum Graphite
Event History
Jun 15, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:07 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-868?
The severity of ZDI-23-868 is high due to its potential for remote code execution.
2
How do I fix ZDI-23-868?
To fix ZDI-23-868, update Ashlar-Vellum Graphite to the latest version provided by the vendor.
3
What type of attack does ZDI-23-868 facilitate?
ZDI-23-868 facilitates remote code execution attacks via malicious pages or files.
4
Is user interaction necessary for ZDI-23-868 exploitation?
Yes, user interaction is required for ZDI-23-868 exploitation, as the target must visit a malicious page or open a malicious file.
5
Which software is affected by ZDI-23-868?
The affected software for ZDI-23-868 is Ashlar-Vellum Graphite.