An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 2022.11. ODA Viewer continues to process invalid or malicious DWF files instead of stopping upon an exception. An attacker can leverage this vulnerability to execute code in the context of the current process.
References
Link | Resource |
---|---|
https://www.opendesign.com/security-advisories | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-1358/ | Third Party Advisory VDB Entry |
https://www.zerodayinitiative.com/advisories/ZDI-21-1360/ | Third Party Advisory VDB Entry |
https://www.zerodayinitiative.com/advisories/ZDI-21-1363/ | Third Party Advisory VDB Entry |
https://www.opendesign.com/security-advisories | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-1358/ | Third Party Advisory VDB Entry |
https://www.zerodayinitiative.com/advisories/ZDI-21-1360/ | Third Party Advisory VDB Entry |
https://www.zerodayinitiative.com/advisories/ZDI-21-1363/ | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 06:28
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.opendesign.com/security-advisories - Vendor Advisory | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-21-1358/ - Third Party Advisory, VDB Entry | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-21-1360/ - Third Party Advisory, VDB Entry | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-21-1363/ - Third Party Advisory, VDB Entry |
Information
Published : 2021-11-14 21:15
Updated : 2024-11-21 06:28
NVD link : CVE-2021-43272
Mitre link : CVE-2021-43272
CVE.ORG link : CVE-2021-43272
JSON object : View
Products Affected
opendesign
- oda_viewer
CWE
CWE-755
Improper Handling of Exceptional Conditions