An issue was discovered in Open Design Alliance Drawings SDK...
Vulnerability Description
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A stack-based buffer overflow vulnerability exists when the recover operation is run with malformed .DXF and .DWG files. This can allow attackers to cause a crash potentially enabling a denial of service attack (Crash, Exit, or Restart) or possible code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-25178
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.opendesign.com/security-advisories
- https://cert-portal.siemens.com/productcert/pdf/ssa-663999.pdf
- https://www.zerodayinitiative.com/advisories/ZDI-21-243/
- https://www.zerodayinitiative.com/advisories/ZDI-21-240/
- https://www.zerodayinitiative.com/advisories/ZDI-21-220/
- https://cert-portal.siemens.com/productcert/pdf/ssa-155599.pdf
More from opendesign
View All →Affected Vendor
opendesign
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.