Impact
Improper null termination in Pardus Pen leads to a buffer overflow during string handling, potentially corrupting adjacent memory. The flaw can cause the application to crash or input to influence memory layout. The weakness aligns with CWE‑170, where incorrect string termination permits uncontrolled buffer usage. No evidence of remote code execution is given, but the overflow could allow local exploit attempts to gain.
Affected Systems
The vulnerability affects the Pardus Pen software from TUBITAK BILGEM Software Technologies Research Institute. Versions up to and including 4.1.5, and any builds prior to 4.2.1, are vulnerable. Later releases are presumed to contain the fix, as no explicit patch details are provided.
Risk and Exploitability
The CVSS score of 3.9 classifies the flaw as low severity, and the EPSS score is below 1%, indicating a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. The likely attack vector supply crafted input locally to trigger the overflow; based that remote exploitation would require additional undisclosed conditions.
OpenCVE Enrichment