Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Datakit recommends user upgrade to v2023.1 https://www.datakit.com/en/crosscad_ware.php or later.
Vendor Workaround
Datakit has identified specific workarounds and mitigations that should be applied to reduce the risk: * Do not open untrusted SLDPRT files with CrossCAD/Ware * Update CrossCAD/Ware to 2023.1 or a later version.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-26517 | Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information. |
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:35:58.720Z
Reserved: 2023-01-23T18:59:04.552Z
Link: CVE-2023-22354
Updated: 2024-08-02T10:07:06.482Z
Status : Modified
Published: 2023-04-20T19:15:07.290
Modified: 2024-11-21T07:44:37.027
Link: CVE-2023-22354
No data.
OpenCVE Enrichment
No data.
EUVD