216.73.217.22

CVE-2024-54028

· Published 02/06/2025 15:15 · Modified 02/06/2025 17:32

Labels: CVE-2024-54028 2025-06-02CVE-2024-54028CWE-191[email protected]

Essential information

Published
02/06/2025 15:15
Modified
02/06/2025 17:32
Author
Creator
CVSS
8.4 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
catdoc / catdoc cpe:2.3:a:catdoc:catdoc:0.95:*:*:*:*:*:*:*

References