In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
References
| Link | Resource |
|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-03 | Third Party Advisory US Government Resource |
Configurations
History
No history.
Information
Published : 2025-02-04 23:15
Updated : 2025-09-16 16:54
NVD link : CVE-2023-40222
Mitre link : CVE-2023-40222
CVE.ORG link : CVE-2023-40222
JSON object : View
Products Affected
ashlar
- cobalt
CWE
CWE-122
Heap-based Buffer Overflow
