Remote Code Execution via CO File Parsing in Ashlar-Vellum Cobalt
Ashlar-Vellum Cobalt has a remote code execution vulnerability when parsing CO files. This lets remote attackers run arbitrary code on affected systems. The target user must visit a harmful page or open a harmful file for this to happen.
The flaw is in how CO files are parsed. The problem is due to not properly checking user-supplied data. This can lead to writing outside the allocated buffer. Attackers can use this vulnerability to execute code in the current process context. It was identified as ZDI-CAN-24867.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ashlar-vellum cobalt |
||
ashlar cobalt 1204.90 |