Heap-based Buffer Overflow in Ashlar-Vellum Graphite VC6 File Parsing
CVE-2024-13051

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
30 December 2024

What is CVE-2024-13051?

A vulnerability exists in the Ashlar-Vellum Graphite software related to the parsing of VC6 files, specifically a heap-based buffer overflow. This flaw arises from the insufficient validation of the length of user-supplied data before it is copied into a heap-based buffer. Attackers can exploit this vulnerability by convincing users to visit a malicious webpage or open a corrupted VC6 file. Successful exploitation allows the attacker to execute arbitrary code within the context of the affected application, posing a significant security risk to installations using the vulnerable product.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-13051 : Heap-based Buffer Overflow in Ashlar-Vellum Graphite VC6 File Parsing