Home

Description

Valentina Studio 9.0.5 Linux contains a buffer overflow vulnerability in the Host field of the connection dialog that allows local attackers to crash the application by supplying an oversized input string. Attackers can trigger the vulnerability by pasting a crafted buffer exceeding 264 bytes into the Host field during server connection attempts, causing a denial of service.

PUBLISHED Reserved 2026-03-21 | Published 2026-03-21 | Updated 2026-03-24 | Assigner VulnCheck




MEDIUM: 6.9CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
MEDIUM: 6.2CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

Out-of-bounds Write

Product status

9.0.5
affected

Credits

Alejandra Sánchez finder

References

www.exploit-db.com/exploits/46439 (ExploitDB-46439) exploit

valentina-db.com/en/ (Official Product Homepage) product

www.valentina-db.com/...rrent/vstudio_x64_lin-deb?format=raw (Product Reference) product

www.vulncheck.com/...io-linux-buffer-overflow-via-host-field (VulnCheck Advisory: Valentina Studio 9.0.5 Linux Buffer Overflow via Host Field) third-party-advisory

cve.org (CVE-2019-25567)

nvd.nist.gov (CVE-2019-25567)

Download JSON