VYPR
Unrated severityNVD Advisory· Published Nov 14, 2021· Updated Aug 4, 2024

CVE-2021-43278

CVE-2021-43278

Description

An Out-of-bounds Read vulnerability exists in the OBJ file reading procedure in Open Design Alliance Drawings SDK before 2022.11. The lack of validating the input length can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds read in ODA Drawings SDK before 2022.11 allows attackers to execute code when processing a crafted OBJ file.

Vulnerability

The Open Design Alliance Drawings SDK before version 2022.11 contains an out-of-bounds read vulnerability in its OBJ file reading procedure [1]. The software fails to validate the input length, which can trigger a read past the end of an allocated buffer when parsing a specially crafted OBJ file. Affected versions: all versions before 2022.11 [1].

Exploitation

An attacker must provide a malicious OBJ file to a target application that uses the vulnerable SDK. No special network position is required beyond the ability to deliver the file (e.g., via email, download, or file sharing). The user must open the malicious OBJ file in an application built with the affected SDK. The lack of input length validation allows the attacker to trigger the out-of-bounds read with no additional privileges or user interaction beyond opening the file [1].

Impact

Successful exploitation allows the attacker to execute arbitrary code in the context of the current process. The out-of-bounds read can be leveraged to achieve code execution, potentially leading to full compromise of the affected application and the user's system [1].

Mitigation

A fix was released in ODA Drawings SDK version 2022.11. Users should upgrade to version 2022.11 or later. No workarounds are described in the available references. The vendor’s security advisory page should be monitored for updates [1].

Not yet disclosed in the available references.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.