Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function CJBig2Image::expand() and results in a memory corruption that leads to code execution when parsing a crafted PDF book.
2021-09-01T18:15:09.053
2024-11-21T06:03:56.100
Modified
CVSSv3.1: 8.6 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | amazon | kindle_firmware | ≤ 5.13.4 | Yes |
Hardware | amazon | kindle | - | No |