Executive brief
Pardus Pen, a tool developed by the TUBITAK BILGEM Software Technologies Research Institute, contains a security flaw in how it handles data strings. An attacker with local access to a system could exploit this to cause the application to crash or potentially access restricted information. This could lead to minor service disruptions or limited data exposure for users of the affected software.
Technical details
A vulnerability classified as CWE-170 (Improper Null Termination) exists in Pardus Pen versions <=4.1.5. The software fails to properly terminate strings with a null character, which can lead to a buffer overflow when the data is subsequently processed. An attacker with local access and low privileges could exploit this flaw, though it requires some level of user interaction. Successful exploitation could result in a denial-of-service (application crash) or limited information disclosure. The issue is addressed in version 4.2.1.
Affected products
- TUBITAK BILGEM Software Technologies Research Institute Pardus Pen <=4.1.5 before 4.2.1
Timeline
- 2026-07-05: advisory: CVE published by NVD and TR-CERT
- 2026-07-05: disclosed