Impact
The vulnerability resides in the arc_parse_canon_t function of the OpenARC library's libopenarc/arc-canon.c component. An attacker can supply crafted input that triggers a null pointer dereference, causing the library to crash. The crash results in a denial of service condition. The weakness is reflected in CWE-476 and CWE-404 entries, indicating improper null handling.
Affected Systems
Trusted Domain Project OpenARC versions up to 1.0.0.Beta1 are affected. The flaw exists in the libopenarc/arc-canon.c module, which is part of the core OpenARC library used for canonicalizing ARC headers during inbound signature validation. Any deployment that loads this library and processes ARC data may be vulnerable.
Risk and Exploitability
The CVSS base score of 6.9 classifies the issue as moderate severity, and no EPSS data is available. The vulnerability is not listed in the CISA KEV catalog. Publicly released exploit code demonstrates that the flaw can be triggered remotely, giving an attacker a wide attack surface. Defenders should treat this as a non-negligible risk that could lead to service interruptions if left unpatched.
OpenCVE Enrichment