IT

Tracker / CVE-2020-7816

CVE-2020-7816

High 7.0

A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker to cause an arbitrary code execution on an affected device.nThe vulnerability is due to a stack overflow read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device.

Affected products and versions

hmtalk daoffice · … → 8.995
hmtalk dava\+ · … → 8.995
hmtalk daview_indy · … → 8.995

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References