CVE-2021-29097

Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*

History

03 Dec 2021, 18:20

Type Values Removed Values Added
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-364/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-364/ - Third Party Advisory, VDB Entry
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-365/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-365/ - Third Party Advisory, VDB Entry
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-368/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-368/ - Third Party Advisory, VDB Entry
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-371/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-371/ - Third Party Advisory, VDB Entry
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-367/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-367/ - Third Party Advisory, VDB Entry
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-363/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-363/ - Third Party Advisory, VDB Entry
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-369/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-369/ - Third Party Advisory, VDB Entry
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-360/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-360/ - Third Party Advisory, VDB Entry

30 Mar 2021, 12:16

Type Values Removed Values Added
References
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-363/ -
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-371/ -
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-364/ -
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-367/ -
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-365/ -
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-368/ -
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-360/ -
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-369/ -

27 Mar 2021, 03:54

Type Values Removed Values Added
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
CWE CWE-119
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CWE CWE-119
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
CWE CWE-119
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CWE CWE-119
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CWE CWE-119
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CWE CWE-119
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CWE CWE-119
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CWE CWE-119
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
CWE CWE-119
CWE CWE-119
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CWE CWE-119
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CWE CWE-119
CWE CWE-119
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*

25 Mar 2021, 22:18

Type Values Removed Values Added
CVSS v2 : 6.8
v3 : 7.8
v2 : unknown
v3 : unknown
CWE CWE-119
CVSS v2 : 6.8
v3 : 7.8
v2 : unknown
v3 : unknown
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CWE CWE-119
CWE CWE-119
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CVSS v2 : 6.8
v3 : 7.8
v2 : unknown
v3 : unknown
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CWE CWE-119
CVSS v2 : 6.8
v3 : 7.8
v2 : unknown
v3 : unknown
CVSS v2 : 6.8
v3 : 7.8
v2 : unknown
v3 : unknown
CWE CWE-119
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CWE CWE-119
CVSS v2 : 6.8
v3 : 7.8
v2 : unknown
v3 : unknown
CWE CWE-119
CVSS v2 : 6.8
v3 : 7.8
v2 : unknown
v3 : unknown
CVSS v2 : 6.8
v3 : 7.8
v2 : unknown
v3 : unknown
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CWE CWE-119
CWE CWE-119
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CVSS v2 : 6.8
v3 : 7.8
v2 : unknown
v3 : unknown
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CVSS v2 : 6.8
v3 : 7.8
v2 : unknown
v3 : unknown
CWE CWE-119
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CVSS v2 : 6.8
v3 : 7.8
v2 : unknown
v3 : unknown
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CWE CWE-119
CVSS v2 : 6.8
v3 : 7.8
v2 : unknown
v3 : unknown
CWE CWE-119
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*

25 Mar 2021, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-25 21:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-29097

Mitre link : CVE-2021-29097

CVE.ORG link : CVE-2021-29097


JSON object : View

Products Affected

esri

  • arcreader
  • arcgis_desktop
  • arcgis
  • arcgis_pro
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow

CWE-122

Heap-based Buffer Overflow