Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An Out-of-bounds Read vulnerability exists in the DGN file reading procedure in Open Design Alliance Drawings SDK before 2022.11. Crafted data in a DGN file and lack of verification of input data can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Open Design Alliance Drawings SDK 缓冲区错误漏洞
Vulnerability Description
Open Design Alliance Drawings SDK是美国Open Design Alliance公司的一款应用于图纸设计的软件开发包。该开发包通过方便的,面向对象的API访问.dwg和.dgn中的数据,提供C++API、支持修复文件、.NET,JAVA,Python开发语言的支持等功能。 ODAViewer 存在安全漏洞,该漏洞源于 DGN 文件中的精心设计的数据可以触发超过分配缓冲区末尾的读取。攻击者可以结合其他漏洞利用此漏洞在当前进程的环境中执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A