Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30933
HistoryJun 12, 2021 - 10:01 p.m.

Remote Code Execution

2021-06-1222:01:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
isync
vulnerability
remote code execution
heap-allocated structure
appenduid response
arbitrary code

EPSS

0.004

Percentile

73.2%

isync is vulnerable to remote code execution. An unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This behavior can be exploited to execute arbitrary code on the client.