CVE-2021-26615: bandisoft ARK library integer overflow vulnerability
ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function because of an integer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security vulnerability?
The vulnerability ID for this security vulnerability is CVE-2021-26615.
What is the title of this vulnerability?
The title of this vulnerability is 'ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAn...'.
What is the description of this vulnerability?
ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function because of an integer overflow.
What is the affected software?
The affected software is Bandisoft Ark Library version 7.13.0.3 and Linux Linux kernel is not vulnerable.
What is the severity of this vulnerability?
The severity of this vulnerability is high with a CVSS score of 8.8.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following link: https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36361