We found results for “”
WS-2016-7081
Good to know:
Date: December 13, 2016
In Kitware/VTK, version v4.2.0 to v7.1.1, there is a potential buffer overflow vulnerability in “vtkSTLReader.cxx”, due to an unbounded “fscanf” file read, which may allow an attacker to crash the program, or even execute arbitrary code on the system.
Language: C++
Severity Score
Severity Score
Weakness Type (CWE)
Buffer Over-read
CWE-126Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | LOCAL |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | HIGH |