Impact
A flaw in JusticeRage Manalyze version 1.0.0 causes an integer underflow when parsing the PE debug section. The mishandling of the misc.Length argument can lead to an out‑of‑bounds access that may corrupt memory or crash the application. The description states that the attack can be performed from remote, indicating that an attacker could supply a malicious PE file over the network and trigger the vulnerability.
Affected Systems
The affected product is JusticeRage Manalyze, a tool used to analyze portable executable files. Only the 1.0.0 release is known to contain the flaw; later versions incorporate the patch listed in commit 3e299685759f4f767088871de58c5d07f98ee382.
Risk and Exploitability
The CVSS score of 5.3 places the bug in the medium severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that there is no known exploitation evidence yet. However, because the attack vector is remote, the likelihood of exploitation remains non‑zero and could lead to denial of service or memory corruption if successful.
OpenCVE Enrichment