CVE-2019-25567
MEDIUMValentina Studio 9.0.5 Linux Buffer Overflow via Host Field
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25567. PoCs published by Alejandra Sánchez.
AI-analyzed exploit summary This PoC demonstrates a buffer overflow vulnerability in Valentina Studio 9.0.5 by writing a 264-byte 'A' character buffer to a file, which when pasted into the 'Host' field during a connection attempt, crashes the application. The exploit is straightforward and targets a stack-based overflow in the host input handling.
Description
Valentina Studio 9.0.5 Linux contains a buffer overflow vulnerability in the Host field of the connection dialog that allows local attackers to crash the application by supplying an oversized input string. Attackers can trigger the vulnerability by pasting a crafted buffer exceeding 264 bytes into the Host field during server connection attempts, causing a denial of service.
Exploits (1)
This PoC demonstrates a buffer overflow vulnerability in Valentina Studio 9.0.5 by writing a 264-byte 'A' character buffer to a file, which when pasted into the 'Host' field during a connection attempt, crashes the application. The exploit is straightforward and targets a stack-based overflow in the host input handling.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H