9.8
CVSSv3

CVE-2023-33863

Published: 07/06/2023 Updated: 25/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

SerialiseValue in RenderDoc prior to 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to 0xffffffffffffffff (SIZE_MAX) and then there is an attempt to add 1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

renderdoc renderdoc

Vendor Advisories

Debian Bug report logs - #1037208 renderdoc: CVE-2023-33863 CVE-2023-33864 CVE-2023-33865 Package: src:renderdoc; Maintainer for src:renderdoc is Debian X Strike Force <debian-x@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 7 Jun 2023 19:00:01 UTC Severity: important Tags: secur ...

Exploits

RenderDoc versions 126 and below suffer from integer underflow, integer overflow, and symlink vulnerabilities ...