PT-2026-99742 · Trusted Domain · Openrc
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Trusted Domain Project OpenARC versions prior to 1.0.0.Beta0
Description
A security flaw in the
libopenarc component allows for a remote attack. The issue resides in the arc parse canon t() function within the libopenarc/arc-canon.c library, where specific manipulation leads to a null pointer dereference, a condition where the software attempts to read from a memory address that is null, typically resulting in a crash.Recommendations
Update to version 1.0.0.Beta0.
As a temporary mitigation, restrict access to the
arc parse canon t() function within the libopenarc component.Exploit
Fix
NULL Pointer Dereference
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openrc