>> NASA Common Data Format "Read32s_64()" Buffer Overflow Vulnerability
Title : NASA Common Data Format "Read32s_64()" Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-1440 CVE ID : CVE-2008-2080
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-05-06
Technical Description
A vulnerability has been identified in NASA Common Data Format (CDF), which could be exploited by attackers to cause a denial of service or execute arbitrary code. This issue is caused by a buffer overflow error in the "Read32s_64()" [src/lib/cdfread64.c] function when processing malformed data, which could be exploited by attackers to crash an affected application or compromise a vulnerable system via a specially crafted CDF file.