CVE-2019-25556
MEDIUMTwistedBrush Pro Studio 24.06 Resize Image Denial of Service
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25556. PoCs published by Alejandra Sánchez.
AI-analyzed exploit summary This PoC exploits a buffer overflow in TwistedBrush Pro Studio 24.06 by generating a malicious input file that crashes the application when pasted into the 'Resize Image' dialog. The exploit leverages a simple overflow with a 1000-byte 'A' buffer to trigger a DoS condition.
Description
TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Resize Image function that allows local attackers to crash the application by supplying an excessively long buffer. Attackers can paste a malicious string into the New Width or New Height field to trigger a buffer overflow that causes the application to crash.
Exploits (1)
This PoC exploits a buffer overflow in TwistedBrush Pro Studio 24.06 by generating a malicious input file that crashes the application when pasted into the 'Resize Image' dialog. The exploit leverages a simple overflow with a 1000-byte 'A' buffer to trigger a DoS condition.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H