CVE-2012-10057
CVSS V2 None
CVSS V3 None
Description
Lattice Semiconductor ispVM System v18.0.2 contains a buffer overflow vulnerability in its handling of .xcf project files. When parsing the version attribute of the ispXCF XML tag, the application fails to properly validate input length, allowing a specially crafted file to overwrite memory on the stack. This can result in arbitrary code execution under the context of the user who opens the file. The vulnerability is triggered locally by opening a malicious .xcf file and does not require elevated privileges.
Overview
- CVE ID
- CVE-2012-10057
- Assigner
- VulnCheck
- Vulnerability Status
- PUBLISHED
- Published Version
- 2025-08-13T20:35:07.498Z
- Last Modified Date
- 2025-08-13T20:35:07.498Z
Weakness Enumerations
References
| Reference URL | Reference Tags |
|---|---|
| https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/ispvm_xcf_ispxcf.rb | exploit |
| https://www.exploit-db.com/exploits/18947 | exploit |
| https://web.archive.org/web/20121014002756/http://secunia.com/advisories/48740/ | technical-description exploit |
| https://www.latticesemi.com/ispvm | product |
| https://www.vulncheck.com/advisories/lattice-semiconductor-ispvm-system-xcf-file-handling-buffer-overflow | third-party-advisory |
Sources
| Source Name | Source URL |
|---|---|
| NIST | https://nvd.nist.gov/vuln/detail/CVE-2012-10057 |
| MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-10057 |
History
| Created | Old Value | New Value | Data Type | Notes |
|---|---|---|---|---|
| 2025-08-14 10:01:34 | Added to TrackCVE |