An integer overflow vulnerability exists in the Compound...
High severity
Unreviewed
Published
Oct 3, 2024
to the GitHub Advisory Database
•
Updated Oct 3, 2024
Description
Published by the National Vulnerability Database
Oct 3, 2024
Published to the GitHub Advisory Database
Oct 3, 2024
Last updated
Oct 3, 2024
An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A specially crafted file can result in an integer overflow when processing the directory from the file that allows for an out-of-bounds index to be used when reading and writing to an array. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
References