CVE-2019-25567

MEDIUM

Valentina Studio 9.0.5 Linux Buffer Overflow via Host Field

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25567. PoCs published by Alejandra Sánchez.

AI-analyzed exploit summary This PoC demonstrates a buffer overflow vulnerability in Valentina Studio 9.0.5 by writing a 264-byte 'A' character buffer to a file, which when pasted into the 'Host' field during a connection attempt, crashes the application. The exploit is straightforward and targets a stack-based overflow in the host input handling.

Description

Valentina Studio 9.0.5 Linux contains a buffer overflow vulnerability in the Host field of the connection dialog that allows local attackers to crash the application by supplying an oversized input string. Attackers can trigger the vulnerability by pasting a crafted buffer exceeding 264 bytes into the Host field during server connection attempts, causing a denial of service.

Exploits (1)

exploitdb WORKING POC
by Alejandra Sánchez · pythondoslinux
https://www.exploit-db.com/exploits/46439

This PoC demonstrates a buffer overflow vulnerability in Valentina Studio 9.0.5 by writing a 264-byte 'A' character buffer to a file, which when pasted into the 'Host' field during a connection attempt, crashes the application. The exploit is straightforward and targets a stack-based overflow in the host input handling.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Valentina Studio 9.0.5
No auth needed
Prerequisites: Python to generate the payload file · User interaction to paste the payload into the 'Host' field
devstral-2 · analyzed Mar 21, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-46439
https://www.exploit-db.com/exploits/46439
Product product
Official Product Homepage
https://valentina-db.com/en/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Valentina Studio 9.0.5 Linux Buffer Overflow via Host Field
https://www.vulncheck.com/advisories/valentina-studio-linux-buffer-overflow-via-host-field

Scores

CVSS v3 6.2
EPSS 0.0018
EPSS Percentile 8.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (2)
valentina-db/studio 9.0.5
Valentina-Db/Valentina Studio 9.0.5
Published Mar 21, 2026
Tracked Since Mar 21, 2026