PT-2022-6687 · Ashlar Vellum · Ashlar-Vellum Graphite

Rocco Calvi

+1

·

Published

2022-10-05

·

Updated

2024-09-18

·

CVE-2023-34308

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ashlar-Vellum Graphite (affected versions not specified)
Description The issue is related to an out-of-bounds write when parsing VC6 files, which can be exploited to execute arbitrary code. This can be achieved by remote attackers if the target visits a malicious page or opens a malicious file, requiring user interaction. The problem stems from the lack of proper validation of user-supplied data, allowing a write past the end of an allocated buffer. An attacker can leverage this to execute code in the context of the current process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-03402
CVE-2023-34308
ZDI-23-868

Affected Products

Ashlar-Vellum Graphite