PT-2023-7352 · Ashlar Vellum · Ashlar-Vellum Graphite

Michael Heinzl

·

Published

2023-10-26

·

Updated

2023-11-06

·

CVE-2023-39936

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ashlar-Vellum Graphite version 13.0.48
Description The issue is related to a lack of proper validation of user-supplied data when parsing VC6 files, which could lead to an out-of-bounds read. This may allow an attacker to execute arbitrary code in the context of the current process by leveraging the vulnerability through specially crafted VC6 files.
Recommendations For Ashlar-Vellum Graphite version 13.0.48, consider disabling the parsing of VC6 files until a patch is available to prevent potential exploitation. Restrict access to the feature that handles VC6 files to minimize the risk of arbitrary code execution. Avoid using the affected application to parse VC6 files from untrusted sources until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2023-08383
CVE-2023-39936

Affected Products

Ashlar-Vellum Graphite