Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DWF file and missing proper checks on received SectionIterator data can trigger an unhandled exception. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code execution.
History

Wed, 04 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Dec 2024 12:00:00 +0000

Type Values Removed Values Added
Description Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DWF file and missing proper checks on received SectionIterator data can trigger an unhandled exception. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code execution.
Title Out-of-bounds Write vulnerability in ODA SDK versions < 2025.10
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 8.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ODA

Published: 2024-12-04T11:40:22.411Z

Updated: 2024-12-04T21:02:00.422Z

Reserved: 2024-09-16T14:09:36.103Z

Link: CVE-2024-8894

cve-icon Vulnrichment

Updated: 2024-12-04T19:18:47.311Z

cve-icon NVD

Status : Received

Published: 2024-12-04T12:15:20.763

Modified: 2024-12-04T12:15:20.763

Link: CVE-2024-8894

cve-icon Redhat

No data.