CVE-2023-33863
Dashboard / Vulnerabilities / CVE-2023-33863
CVE-2023-33863
Summary:
Details: SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to 0xffffffffffffffff (SIZE_MAX) and then there is an attempt to add 1.
References: http://packetstormsecurity.com/files/172804/RenderDoc-1.26-Local-Privilege-Escalation-Remote-Code-Execution.html, https://lists.debian.org/debian-lts-announce/2024/12/msg00008.html, https://renderdoc.org/, https://www.qualys.com/2023/06/06/renderdoc/renderdoc.txt, https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/33xxx/CVE-2023-33863.json, https://nvd.nist.gov/vuln/detail/CVE-2023-33863, https://security.gentoo.org/glsa/202311-10, http://seclists.org/fulldisclosure/2023/Jun/2, https://lists.debian.org/debian-lts-announce/2023/07/msg00023.html
Affected packages
Package
Name:
Purl:
