PT-2022-9783 · Unknown · Ark Library

Published

2022-06-01

·

Updated

2023-06-26

·

CVE-2021-26635

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ark library (affected versions not specified)
Description The issue arises from the incorrect use of data types in the code that verifies file sizes in the ark library. This allows an attacker to manipulate the offset read from the target file, potentially causing a stack buffer overflow. As a result, an attacker could perform remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Type Confusion

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2021-26635

Affected Products

Ark Library