Vulnerability CVE-2018-18224


Published: 2018-10-19   Modified: 2018-10-20

Description:
A vulnerability exists in the file reading procedure in Open Design Alliance Drawings SDK 2019Update1 on non-Windows platforms in which attackers could perform read operations past the end, or before the beginning, of the intended buffer. This can allow attackers to obtain sensitive information from process memory or cause a crash.

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.8/10
4.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
Partial
Affected software
Oracle -> Outside in technology 
Opendesign -> Drawings sdk 

 References:
http://www.securityfocus.com/bid/105603
https://www.opendesign.com/security-advisories
https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html

Copyright 2024, cxsecurity.com

 

Back to Top