VYPR
Unrated severityNVD Advisory· Published Apr 26, 2021· Updated Aug 3, 2024

CVE-2021-31784

CVE-2021-31784

Description

An out-of-bounds write vulnerability exists in the file-reading procedure in Open Design Alliance Drawings SDK before 2021.6 on all supported by ODA platforms in static configuration. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart) or possible code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds write in ODA Drawings SDK static builds before 2021.6 can enable denial of service or potential code execution via crafted files.

Vulnerability

An out-of-bounds write vulnerability exists in the file-reading procedure of Open Design Alliance (ODA) Drawings SDK versions before 2021.6 when built in static configuration [1]. The bug is reachable when the SDK processes a specially crafted drawing file; no special configuration beyond using a static build of the SDK is required.

Exploitation

An attacker needs only the ability to supply a malicious drawing file to an application using the vulnerable SDK [1]. No authentication or elevated privileges are required. The attack vector is file-based: the victim opens or processes the crafted file, triggering the out-of-bounds write during parsing.

Impact

Successful exploitation can cause a crash (denial of service), or depending on the memory layout, may enable arbitrary code execution in the context of the affected application [1]. The impact is limited to the process hosting the ODA SDK.

Mitigation

Users should upgrade to ODA Drawings SDK version 2021.6 or later [1]. No workaround is described in the available references; if upgrading is not immediately possible, avoid opening untrusted drawing files.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.