Integer Overflow Vulnerability in Ashlar-Vellum Cobalt File Parsing
CVE-2025-7982
7.8HIGH
What is CVE-2025-7982?
The Ashlar-Vellum Cobalt product has a vulnerability in its LI file parsing mechanism, allowing attackers to perform remote code execution. This issue stems from inadequate validation of user-supplied data, leading to an integer overflow that can occur before buffer allocation. Successful exploitation requires user interaction, such as visiting a malicious website or opening a compromised file. Attackers can use this vulnerability to execute arbitrary code within the context of the target process, posing significant security risks to affected installations.
Affected Version(s)
Cobalt 1204.96