PT-2008-6774 · Sawstudio · Sawstudio

Encrypt3D.M!Nd

·

Published

2008-12-26

·

Updated

2017-09-29

·

CVE-2008-5722

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAWStudio version 3.9i
Description The issue is related to a buffer overflow that can be triggered by a long SAWSTUDIO PREFERENCES STRUCT value in a .prf (preferences) file, potentially allowing user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.
Recommendations For SAWStudio version 3.9i, consider avoiding the use of long SAWSTUDIO PREFERENCES STRUCT values in .prf files until a patch is available. As a temporary workaround, restrict the handling of .prf files to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5722

Affected Products

Sawstudio