CVE-2023-40294

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Aug 14, 2023
Updated: Aug 21, 2023
CWE ID 787

Summary

CVE-2023-40294 is a newly identified vulnerability affecting the libboron library in Boron 2.0.8. This issue involves a heap-based buffer overflow in the ur_parseBlockI function located at i_parse_blk.c. Maliciously crafted input data can exploit this vulnerability to execute arbitrary code and potentially gain unauthorized access to a system. Successful exploitation could lead to serious security implications such as data theft or system compromise. Users are advised to update their Boron installations as soon as possible to mitigate the risk of this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share