PT-2017-13589 · Cyberlink · Cyberlink Labelprint

F3Ci

+1

·

Publicado

2017-09-23

·

Atualizado

2018-12-14

·

CVE-2017-14627

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CyberLink LabelPrint version 2.5
Description The issue allows remote attackers to execute arbitrary code via specific parameters in an lpp project file, including the author and name parameters inside the INFORMATION tag, the artist parameter inside the TRACK tag, or the default parameter inside the TEXT tag.
Recommendations For CyberLink LabelPrint version 2.5, consider avoiding the use of the author, name, artist, and default parameters in lpp project files until a fix is available. Restrict access to the lpp project file handling functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14627

Produtos afetados

Cyberlink Labelprint