An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used by the Fat structure in a crafted DGN file leads to an out-of-bounds write. An attacker can leverage this vulnerability to execute code in the context of the current process.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.opendesign.com/security-advisories | vendor advisory |