Impact
OpenAPV versions prior to 1.1.1.0 contain a heap-based buffer overflow in the read_bitstream routine, which can corrupt memory if an attacker supplies a crafted bitstream. This weakness is classified as CWE-190, another name for integer overflow or wraparound, leading to potential arbitrary code execution or denial of service depending on how the corrupted data is handled.
Affected Systems
Vulnerable instances of the OpenAPV tool released by the Academy Software Foundation. All releases before 1.1.1.0 are affected; the recommended safe releases are v1.1.1.0 or newer.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and no EPSS score is currently available, suggesting limited knowledge about exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via unsanitized user input that triggers the read_bitstream routine, either locally or from a remote source if the tool processes network data.
OpenCVE Enrichment