In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.

Project Subscriptions

Vendors Products
Advisories
Source ID Title
EUVD EUVD EUVD-2023-44819 In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Fixes

Solution

Ashlar-Vellum recommends users apply the following mitigations to help reduce risk: * Install the latest version of Graphite https://download.ashlar.com/v13/gr.html . * Update to the latest version for Cobalt, Xenon, Lithium, and Argon by installing v12 SP12 Alpha https://download.ashlar.com/v12/mod-history.html  Build (1204.200) (Jan 22, 2025). * Only open files from trusted sources.


Workaround

No workaround given by the vendor.

History

Tue, 16 Sep 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Ashlar
Ashlar cobalt
CPEs cpe:2.3:a:ashlar:cobalt:*:*:*:*:*:*:*:*
Vendors & Products Ashlar
Ashlar cobalt

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00018}

epss

{'score': 0.00022}


Thu, 06 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Feb 2025 22:30:00 +0000

Type Values Removed Values Added
Description In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Title Ashlar-Vellum Cobalt, Xenon, Argon, Lithium Heap-based Buffer Overflow
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-02-05T19:44:07.344Z

Reserved: 2023-08-10T19:30:27.396Z

Link: CVE-2023-40222

cve-icon Vulnrichment

Updated: 2025-02-05T19:43:49.641Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-04T23:15:08.413

Modified: 2025-09-16T16:54:40.543

Link: CVE-2023-40222

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses