PT-2023-21093 · Diagon · Diagon

Francesco Benvenuto

·

Published

2023-07-05

·

Updated

2023-08-02

·

CVE-2023-27390

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Diagon version 1.0.139
Description A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality. This issue can be triggered by a specially crafted markdown file or network request, potentially leading to arbitrary code execution or a heap buffer overflow. An attacker can exploit this by sending a malicious network request or a victim can be affected by opening a malicious file.
Recommendations For Diagon version 1.0.139, consider disabling the Sequence::DrawText functionality until a patch is available to prevent potential exploitation. Restrict access to handling markdown files and network requests to minimize the risk of triggering the vulnerability.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2023-27390

Affected Products

Diagon