In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target file due to the wrong use of the data type. An attacker could use this vulnerability to cause a stack buffer overflow and as a result, perform an attack such as remote code execution.
References
Link | Resource |
---|---|
https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66747 | Third Party Advisory |
Configurations
Information
Published : 2022-06-02 07:15
Updated : 2022-06-09 09:45
NVD link : CVE-2021-26635
Mitre link : CVE-2021-26635
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
bandisoft
- ark_library