ZDI-CAN-18908: ZDI-23-866: (0Day) Ashlar-Vellum Graphite VC6 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published Jun 15, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Ashlar-Vellum Graphite
Event History
Jun 15, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:07 AM
Frequently Asked Questions
1
What is the severity of ZDI-CAN-18908?
The severity of ZDI-CAN-18908 is critical due to the potential for remote code execution.
2
How do I fix ZDI-CAN-18908?
To fix ZDI-CAN-18908, users should update Ashlar-Vellum Graphite to the latest version that addresses the vulnerability.
3
What types of attacks does ZDI-CAN-18908 enable?
ZDI-CAN-18908 enables remote attackers to execute arbitrary code on affected installations requiring user interaction.
4
Who is affected by ZDI-CAN-18908?
Users of Ashlar-Vellum Graphite are affected by ZDI-CAN-18908.
5
What do I need to do to be vulnerable to ZDI-CAN-18908?
To be vulnerable to ZDI-CAN-18908, a user must visit a malicious page or open a malicious file.