Vulnerability Description
In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target file due to the wrong use of the data type. An attacker could use this vulnerability to cause a stack buffer overflow and as a result, perform an attack such as remote code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bandisoft | Ark Library | < 7.17 |
Related Weaknesses (CWE)
References
- https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66747Broken LinkThird Party Advisory
- https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66747Broken LinkThird Party Advisory
FAQ
What is CVE-2021-26635?
CVE-2021-26635 is a vulnerability with a CVSS score of 7.8 (HIGH). In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target file due to the wrong use of the data type. An attacker could use this vulnerab...
How severe is CVE-2021-26635?
CVE-2021-26635 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26635?
Check the references section above for vendor advisories and patch information. Affected products include: Bandisoft Ark Library.