CNNVD-202509-2656 Information
Sep 17, 2025
cve
CNNVD ID
CNNVD-202509-2656
Related CVE
- CNNVD Published: 2025-09-17
Description (Chinese)
Ashlar-Vellum Cobalt是Ashlar-Vellum公司的一种基于参数的计算机辅助设计和 3D 建模程序。 Ashlar-Vellum Cobalt存在输入验证错误漏洞,该漏洞源于解析LI文件时缺少对用户提供数据的验证,可能导致整数溢出和远程代码执行。
Description (English)
Ashlar-Vellam Cobalt is an argument-based computer-aided design and 3D modelling program for Ashlar-Vellum. Ashlar-Vellam Cobalt has an input validation bug that results from a lack of validation of the data provided by users when the LI file is deciphered, which may lead to integer spills and remote code execution.
Hazard Level
Medium
Vulnerability Type
输入验证错误
Affected Vendor
Ashlar-Vellum
Published
2025-09-17
Last Modified
2026-02-24
References
https://www.zerodayinitiative.com/advisories/ZDI-25-630/
Share on: