VYPR
Unrated severityNVD Advisory· Published Dec 21, 2021· Updated Aug 4, 2024

CVE-2021-44860

CVE-2021-44860

Description

An out-of-bounds read vulnerability exists when reading a TIF file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TIF files. An unchecked input data from a crafted TIF file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute code in the context of the current process.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Out-of-bounds read in Open Design Alliance Drawings SDK before 2022.12 when loading crafted TIF files may allow arbitrary code execution.

Vulnerability

An out-of-bounds read vulnerability exists in the Open Design Alliance Drawings SDK before version 2022.12 when processing TIF files. The specific issue occurs after loading a TIF file where unchecked input data leads to reading beyond the allocated buffer. Versions prior to 2022.12 are affected [1].

Exploitation

An attacker can exploit this vulnerability by supplying a specially crafted TIF file to an application that uses the vulnerable SDK. No special network position or authentication is required; the attacker only needs to convince the victim to open the malicious file (e.g., via email attachment or web download). The out-of-bounds read occurs during file parsing.

Impact

Successful exploitation could allow an attacker to execute arbitrary code in the context of the current process. This can lead to full compromise of the affected system, including data disclosure, modification, or further attacks [1].

Mitigation

The vulnerability is fixed in ODA Drawings SDK version 2022.12. Users should upgrade to this version or later. If upgrading is not possible, avoid opening TIF files from untrusted sources. No other workarounds are documented [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.