The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process.
No analysis available yet.
Vendor Solution
Horner Automation recommends upgrading the following software: * Cscape: Update to v9.90 SP9 https://hornerautomation.com/cscape-software/ * Cscape Envision RV: Update to v4.80 https://hornerautomation.com/product/cscape-envision-rv/
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-31642 | The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. |
Tue, 07 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-07T18:34:58.614Z
Reserved: 2023-05-09T17:30:31.026Z
Link: CVE-2023-27916
Updated: 2024-08-02T12:23:30.579Z
Status : Modified
Published: 2023-06-06T17:15:13.200
Modified: 2024-11-21T07:53:41.590
Link: CVE-2023-27916
No data.
OpenCVE Enrichment
No data.
EUVD