PT-2017-13589 · Cyberlink · Cyberlink Labelprint

F3Ci

+1

·

Published

2017-09-23

·

Updated

2018-12-14

·

CVE-2017-14627

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CyberLink LabelPrint version 2.5
Description The issue allows remote attackers to execute arbitrary code via specific parameters in an lpp project file, including the author and name parameters inside the INFORMATION tag, the artist parameter inside the TRACK tag, or the default parameter inside the TEXT tag.
Recommendations For CyberLink LabelPrint version 2.5, consider avoiding the use of the author, name, artist, and default parameters in lpp project files until a fix is available. Restrict access to the lpp project file handling functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14627

Affected Products

Cyberlink Labelprint