CVE-2013-3928

critical
Published 2014-03-11 · Modified 2026-05-06
CVSS v3
CVSS v2
9.3
VIR risk
9.3

Description

Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: PSIRT-CNA@flexerasoftware.com — http://secunia.com/advisories/53773

Application impact

VendorProductVersionsFixed
jpchachachasys_draw_ies{"endIncluding":"4.10.01"}
jpchachachasys_draw_ies4.00.01
jpchachachasys_draw_ies4.01.01
jpchachachasys_draw_ies4.02.01
jpchachachasys_draw_ies4.03.02
jpchachachasys_draw_ies4.04.01
jpchachachasys_draw_ies4.06.02

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.