ZDI-CAN-19142: ZDI-23-125: Open Design Alliance (ODA) Drawing SDK DWG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Open Design Alliance (ODA) Drawing SDK. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19142?
The severity of ZDI-CAN-19142 is critical due to its potential to allow remote code execution.
How do I fix ZDI-CAN-19142?
To mitigate ZDI-CAN-19142, ensure that you apply the latest security updates provided by the Open Design Alliance.
Who is affected by ZDI-CAN-19142?
Any user of the Open Design Alliance Drawing SDK is potentially vulnerable to ZDI-CAN-19142.
What type of attack does ZDI-CAN-19142 enable?
ZDI-CAN-19142 enables remote attackers to execute arbitrary code on vulnerable systems.
Is user interaction required to exploit ZDI-CAN-19142?
Yes, user interaction is required as a target must visit a malicious page or open a malicious file for exploitation.