PT-2020-19949 · Bitdefender · Bitdefender Engines
0Xlandave
+1
·
Published
2020-10-01
·
Updated
2020-10-14
·
CVE-2020-8109
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Bitdefender Engines versions prior to 7.84892
Description
A vulnerability has been discovered in the ace.xmd parser due to a lack of proper validation of user-supplied data. This can result in a write past the end of an allocated buffer, leading to denial-of-service.
Recommendations
For Bitdefender Engines versions prior to 7.84892, update to a version later than 7.84892 to resolve the issue. As a temporary workaround, consider restricting the input to the ace.xmd parser to prevent malicious data from being processed.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitdefender Engines