ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function because of an integer overflow.
2021-11-26T17:15:07.683
2024-11-21T05:56:35.733
Modified
CVSSv3.1: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | bandisoft | ark_library | 7.13.0.3 | Yes |
Operating System | linux | linux_kernel | - | No |