CVE-2021-26603: bandisoft ARK library heap overflow vulnerability
Published Sep 9, 2021
·Updated
A heap overflow issue was found in ARK library of bandisoft Co., Ltd when the Ark_DigPathA function parsed a file path. This vulnerability is due to missing support for string length check.
Affected Software
2 affected components
Bandisoft ARK Library<7.13.0.3
Microsoft Windows
Event History
Sep 9, 2021
CVE Published
via MITRE·11:16 AM
Data Sourced
via MITRE·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-26603?
CVE-2021-26603 is a heap overflow vulnerability found in the ARK library of Bandisoft Co., Ltd.
2
How does CVE-2021-26603 impact Bandisoft ARK Library?
CVE-2021-26603 can lead to a heap overflow in Bandisoft ARK Library when the Ark_DigPathA function parses a file path.
3
What causes CVE-2021-26603?
CVE-2021-26603 is caused by missing support for string length check in the ARK library of Bandisoft Co., Ltd.
4
What is the severity of CVE-2021-26603?
CVE-2021-26603 has a severity score of 7.8 (high).
5
How can I fix CVE-2021-26603?
To fix CVE-2021-26603, update the Bandisoft ARK Library to version 7.13.0.3 or later.