An integer overflow vulnerability exists in the Compound...
High severity
Unreviewed
Published
Oct 3, 2024
to the GitHub Advisory Database
•
Updated Oct 3, 2024
Description
Published by the National Vulnerability Database
Oct 3, 2024
Published to the GitHub Advisory Database
Oct 3, 2024
Last updated
Oct 3, 2024
An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
References