Published:2025/01/29  Last Updated:2025/01/29

JVN#23839833
SXF Common Library vulnerable to improper input data handling

Overview

SXF Common Library provided by General Incorporated Association OCF is vulnerable to improper input data handling.

Products Affected

  • SXF Common Library all versions

Description

SXF Common Library provided by General Incorporated Association OCF is vulnerable to improper input data handling (CWE-237).

Impact

If a product using the library reads a crafted file, the product may be crashed.

Solution

Apply the workaround
Applying the following workaround may mitigate the impact of this vulnerability.

  • Do not read untrusted files

Vendor Status

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

CVSS v3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Base Score: 3.3
Attack Vector(AV) Physical (P) Local (L) Adjacent (A) Network (N)
Attack Complexity(AC) High (H) Low (L)
Privileges Required(PR) High (H) Low (L) None (N)
User Interaction(UI) Required (R) None (N)
Scope(S) Unchanged (U) Changed (C)
Confidentiality Impact(C) None (N) Low (L) High (H)
Integrity Impact(I) None (N) Low (L) High (H)
Availability Impact(A) None (N) Low (L) High (H)

Credit

Koh M. Nakagawa reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2025-24336
JVN iPedia JVNDB-2025-000007