A vulnerability exists in the file reading procedure in Open Design Alliance Drawings SDK 2019Update1 on non-Windows platforms in which attackers could perform read operations past the end, or before the beginning, of the intended buffer. This can allow attackers to obtain sensitive information from process memory or cause a crash.
References
Link | Resource |
---|---|
https://www.opendesign.com/security-advisories | Vendor Advisory |
http://www.securityfocus.com/bid/105603 | Third Party Advisory VDB Entry |
https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html | Vendor Advisory |
Information
Published : 2018-10-19 15:29
Updated : 2020-08-24 10:37
NVD link : CVE-2018-18224
Mitre link : CVE-2018-18224
JSON object : View
CWE
CWE-125
Out-of-bounds Read
Products Affected
oracle
- outside_in_technology
opendesign
- drawings_sdk