#VU110180 Integer underflow in catdoc - CVE-2024-54028
Published: June 3, 2025
catdoc
wagner.pp
Description
The vulnerability allows a local attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer underflow in the OLE Document DIFAT Parser functionality. A local attacker can use a specially crafted file, trigger integer underflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.