CVE-2018-18224 Information
Feb 14, 2021
cve
Description
A vulnerability exists in the file reading procedure in Open Design Alliance Drawings SDK 2019Update1 on non-Windows platforms in which attackers could perform read operations past the end or before the beginning of the intended buffer. This can allow attackers to obtain sensitive information from process memory or cause a crash.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Reference
http://www.securityfocus.com/bid/105603 https://www.opendesign.com/security-advisories https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
HIGH
Base Severity
8.1
Share on: