Impact
Improper null termination in Pardus Pen leads to a buffer overflow during string handling, potentially corrupting adjacent memory. This flaw can cause the application to crash or allow input to influence memory layout. The weakness aligns with CWE‑170, where incorrect string termination permits uncontrolled buffer usage. No evidence of remote code execution is given, and the overflow may enable local exploit attempts to gain.
Affected Systems
The vulnerability affects the Pardus Pen software from TUBITAK BILGEM Software Technologies Research Institute. Versions up to and including 4.1.5, and any builds prior to 4.2.1, are vulnerable. It is inferred that later releases contain the fix, although the CVE description does not confirm this.
Risk and Exploitability
The CVSS score of 3.9 classifies the flaw as low severity, and the EPSS score is below 1%, indicating a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. It is inferred that the likely attack vector is local through crafted input, as the CVE description does not mention remote exploitation; remote exploitation would require additional undisclosed conditions.
OpenCVE Enrichment