PT-2021-7816 · Xmill · Xmill

·

CVE-2021-21830

·

Published

2021-02-10

·

Updated

2024-08-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xmill version 0.7
Description A heap-based buffer overflow issue exists in the XML Decompression LabelDict::Load functionality. This can be triggered by a specially crafted XMI file, potentially leading to remote code execution. An attacker can exploit this by providing a malicious file.
Recommendations For Xmill version 0.7, consider disabling the LabelDict::Load functionality until a patch is available to prevent potential remote code execution. Restrict access to the XML Decompression feature to minimize the risk of exploitation. Avoid using the LabelDict::Load function with untrusted XMI files until the issue is resolved.

Exploit

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03270
CVE-2021-21830

Affected Products

Xmill