ZeroHour

CVE-2021-26635

CVSS 3.1
7.8 high
EPSS
1%p65
Published
()
Modified
Description

In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target file due to the wrong use of the data type. An attacker could use this vulnerability to cause a stack buffer overflow and as a result, perform an attack such as remote code execution.

Vendors
bandisoft
Products
ark library
Weakness
CWE-121, CWE-843
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.