CVE-2022-2949

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/12/2022
Last modified:
07/11/2023

Description

<br /> <br /> <br /> Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to increment a counter leading to memory corruption.<br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:altair:hyperview_player:*:*:*:*:*:*:*:* 2021.1.0.27 (including)


References to Advisories, Solutions, and Tools