PT-2017-12351 · Computerinsel · Computerinsel Photoline
Published
2017-10-05
·
Updated
2022-04-19
·
CVE-2017-12106
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Computerinsel Photoline version 20.02
Description
A memory corruption issue exists in the .TGA parsing functionality. This can be triggered by a specially crafted .TGA file, leading to an out of bounds write and potentially resulting in code execution. An attacker can exploit this by sending a specific .TGA file.
Recommendations
For Computerinsel Photoline version 20.02, consider avoiding the use of .TGA files until a patch is available. As a temporary workaround, restrict the ability to open or process .TGA files to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Computerinsel Photoline