Vulnerability Description
Heap-based buffer overflow in the ReadDIB function in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows context-dependent attackers to execute arbitrary code via the BITMAPINFOHEADER.biClrUsed field in a BMP file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0993.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Embarcadero | Embarcadero C\+\+Builder Xe6 | 20.0.15596.9843 |
| Embarcadero | Embarcadero Delphi Xe6 | 20.0.15596.9843 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2014/Sep/57
- http://support.embarcadero.com/article/44015ExploitVendor Advisory
- http://www.coresecurity.com/advisories/delphi-and-c-builder-vcl-library-heap-buf
- http://seclists.org/fulldisclosure/2014/Sep/57
- http://support.embarcadero.com/article/44015ExploitVendor Advisory
- http://www.coresecurity.com/advisories/delphi-and-c-builder-vcl-library-heap-buf
FAQ
What is CVE-2014-0994?
CVE-2014-0994 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Heap-based buffer overflow in the ReadDIB function in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE...
How severe is CVE-2014-0994?
CVE-2014-0994 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0994?
Check the references section above for vendor advisories and patch information. Affected products include: Embarcadero Embarcadero C\+\+Builder Xe6, Embarcadero Embarcadero Delphi Xe6.