PT-2017-12351 · Computerinsel · Computerinsel Photoline

Published

2017-10-05

·

Updated

2022-04-19

·

CVE-2017-12106

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Computerinsel Photoline version 20.02
Description A memory corruption issue exists in the .TGA parsing functionality. This can be triggered by a specially crafted .TGA file, leading to an out of bounds write and potentially resulting in code execution. An attacker can exploit this by sending a specific .TGA file.
Recommendations For Computerinsel Photoline version 20.02, consider avoiding the use of .TGA files until a patch is available. As a temporary workaround, restrict the ability to open or process .TGA files to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-12106

Affected Products

Computerinsel Photoline