PT-2025-23528 · Catdoc+3 · Catdoc+3

A Member

·

Published

2025-06-02

·

Updated

2025-10-07

·

CVE-2024-54028

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions catdoc version 0.95
Description An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Recommendations For catdoc version 0.95, consider avoiding the use of the OLE Document DIFAT Parser functionality until a patch is available. As a temporary workaround, restrict the processing of malformed files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Underflow

Weakness Enumeration

Related Identifiers

BDU:2025-12943
CVE-2024-54028
DLA-4234-1
DSA-5953-1
MGASA-2025-0202

Affected Products

Astra Linux
Debian
Red Os
Catdoc