PT-2013-5318 · Icofx · Icofx
Fernando Miranda
+1
·
Published
2013-12-13
·
Updated
2021-06-07
·
CVE-2013-4988
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IcoFX versions 2.5 and earlier
Description
The issue allows remote attackers to execute arbitrary code via a long
idCount value in an ICONDIR structure in an ICO file. This is a stack-based buffer overflow.Recommendations
For IcoFX versions 2.5 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Icofx