V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CGamenDataRom::set_mr400_strc function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://monitouch.fujielectric.com/site/download-e/09vsft6_inf/Search.php | release notes vendor advisory |
https://jvn.jp/en/vu/JVNVU97228144/ | third party advisory |