PT-2021-22892 · R3D Sdk+1 · R3D Sdk+1
Published
2021-12-22
·
Updated
2022-09-03
·
CVE-2021-40417
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DPDecoder service (affected versions not specified)
Description
The issue arises when the DPDecoder service parses a submitted file as a job, using decoding parameters and fields parsed by the R3D SDK to calculate a heap buffer size. An integer overflow in this calculation can lead to an undersized heap buffer allocation. When this buffer is written to, a heap-based buffer overflow occurs, potentially resulting in code execution under the context of the application.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dpdecoder Service
R3D Sdk