PT-2023-21093 · Diagon · Diagon
Francesco Benvenuto
·
Published
2023-07-05
·
Updated
2023-08-02
·
CVE-2023-27390
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Diagon version 1.0.139
Description
A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality. This issue can be triggered by a specially crafted markdown file or network request, potentially leading to arbitrary code execution or a heap buffer overflow. An attacker can exploit this by sending a malicious network request or a victim can be affected by opening a malicious file.
Recommendations
For Diagon version 1.0.139, consider disabling the Sequence::DrawText functionality until a patch is available to prevent potential exploitation. Restrict access to handling markdown files and network requests to minimize the risk of triggering the vulnerability.
Exploit
Fix
Memory Corruption
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Diagon