Description
Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerability when loading .gdt files. A crafted .gdt file can trigger a buffer overflow during file parsing, allowing an attacker to crash the application or execute malicious code on the underlying system.
Problem types
Product status
Any version before 7.5.3
Any version before 7.2.5.0
Credits
Mario Ceballos
References
static.draeger.com/...C-Vision-Product-Security-Advisory.pdf
www.vulncheck.com/...-of-bounds-write-via-malicious-gdt-file