Zangband · Zangband · CVE-2021-40589
**Name of the Vulnerable Software and Affected Versions**
ZAngband zangband-data version 2.7.5
**Description**
The issue is an integer underflow vulnerability located in src/tk/plat.c, specifically through the variable `fileheader.bfOffBits`.
**Recommendations**
For ZAngband zangband-data version 2.7.5, consider restricting access to the vulnerable `fileheader.bfOffBits` variable in src/tk/plat.c until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.