Description
CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can create a malformed JPG file with an oversized buffer and trigger the crash through the import functionality during the image processing workflow.
Problem types
Sensitive Information in Resource Not Removed Before Reuse
Product status
Credits
Alejandra Sánchez
References
www.exploit-db.com/exploits/46862 (ExploitDB-46862)
cewe-photoworld.com/ (Official Product Homepage)
www.vulncheck.com/...r-denial-of-service-via-malformed-image (VulnCheck Advisory: CEWE PHOTO IMPORTER 6.4.3 Denial of Service via Malformed Image)