CVE-2024-54028: Integer Underflow
An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54028?
The severity of CVE-2024-54028 is considered high due to its potential for causing heap-based memory corruption.
How do I fix CVE-2024-54028?
To fix CVE-2024-54028, update CatDoc to the latest version that addresses this vulnerability.
What impact does CVE-2024-54028 have on systems using CatDoc?
CVE-2024-54028 can lead to arbitrary code execution if an attacker supplies a specially crafted malformed file.
Is CatDoc version 0.95 safe from CVE-2024-54028?
No, CatDoc version 0.95 is vulnerable to CVE-2024-54028 and should be updated to a patched version.
How can an attacker exploit CVE-2024-54028?
An attacker can exploit CVE-2024-54028 by supplying a malformed OLE document file to trigger the integer underflow vulnerability.