vendor:
Zahir Enterprise Plus
by:
modpr0be
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: Zahir Enterprise Plus
Affected Version From: 6 (build 10b)
Affected Version To: 6 (build 10b)
Patch Exists: NO
Related CWE:
CPE: a:zahir:enterprise_plus:6
Platforms Tested: Windows 7 x86/64bit
2018
Zahir Enterprise Plus 6 build 10b โ Buffer Overflow (SEH)
Vulnerability occurs when the Zahir cannot handle large inputs and anomalies crafted CSV file. The Zahir main program failed to process the CR LF (Carriage Return Line Feed) characters which caused the Zahir main program to crash.
Mitigation:
Apply the latest patch or update to a fixed version of the software.