An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code.
References
Link | Resource |
---|---|
https://www.opendesign.com/security-advisories | Vendor Advisory |
https://www.opendesign.com/security-advisories | Vendor Advisory |
Configurations
History
21 Nov 2024, 07:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.opendesign.com/security-advisories - Vendor Advisory |
Information
Published : 2023-04-10 20:15
Updated : 2024-11-21 07:51
NVD link : CVE-2023-26495
Mitre link : CVE-2023-26495
CVE.ORG link : CVE-2023-26495
JSON object : View
Products Affected
opendesign
- drawings_sdk
CWE
CWE-416
Use After Free