CVE-2021-26635

HIGH

Bandisoft ARK Library < 7.17 - Type Confusion leading to Stack Buffer Overflow

Title source: llm
STIX 2.1

Description

In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target file due to the wrong use of the data type. An attacker could use this vulnerability to cause a stack buffer overflow and as a result, perform an attack such as remote code execution.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0112
EPSS Percentile 62.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-121 CWE-843
Status published
Products (1)
bandisoft/ark_library < 7.17
Published Jun 02, 2022
Tracked Since Feb 18, 2026