CVE-2018-25279
MEDIUMjiNa OCR Image to Text 1.0 Denial of Service via PNG
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25279. PoCs published by Gionathan Reale.
AI-analyzed exploit summary This Python script generates a malformed PNG file with an oversized buffer (6000 'A' characters) to trigger a denial-of-service (DoS) crash in jiNa OCR Image to Text 1.0 when the file is processed. The exploit leverages a buffer overflow vulnerability to destabilize the application.
Description
jiNa OCR Image to Text 1.0 contains a denial of service vulnerability that allows local attackers to crash the application by processing a malformed PNG file. Attackers can create a specially crafted PNG file with an oversized buffer and trigger the crash when the application attempts to convert the file to PDF.
Exploits (1)
This Python script generates a malformed PNG file with an oversized buffer (6000 'A' characters) to trigger a denial-of-service (DoS) crash in jiNa OCR Image to Text 1.0 when the file is processed. The exploit leverages a buffer overflow vulnerability to destabilize the application.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H