
We found results for “”
WS-2016-7081
Date: December 13, 2016
In Kitware/VTK, version v4.2.0 to v7.1.1, there is a potential buffer overflow vulnerability in “vtkSTLReader.cxx”, due to an unbounded “fscanf” file read, which may allow an attacker to crash the program, or even execute arbitrary code on the system.
Language: C++
Severity Score
Severity Score
Weakness Type (CWE)
Buffer Over-read
CWE-126CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | LOCAL |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | HIGH |