Aller au contenu

Fiche vulnérabilité

CVE-2021-43277 : faille élevée opendesign oda prc software… (CVSS 7.8)

Description

An out-of-bounds read vulnerability exists in the U3D file reading procedure in Open Design Alliance PRC SDK before 2022.10. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
14 nov. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • opendesign oda prc software development kit

Références

Rechercher une autre vulnérabilité dans la base CVE