Vulnerabilities > CVE-2022-2950 - Use of Uninitialized Resource vulnerability in Altair Hyperview Player 2021.1.0.27
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to increment a counter leading to memory corruption.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |