vendor:
CdCatalog
by:
Ihsan Sencan
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: CdCatalog
Affected Version From: 2.3.1
Affected Version To: 2.3.1
Patch Exists: NO
Related CWE: N/A
CPE: a:cdcat:cdcat:2.3.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2018
CdCatalog 2.3.1 – Denial of Service (PoC)
CdCatalog 2.3.1 is vulnerable to a denial of service attack when a maliciously crafted .hcf file is opened. By creating a file with a length of 21 bytes, the application will crash when the file is opened.
Mitigation:
No known mitigation is available for this vulnerability.