vendor:
Blob Studio
by:
Ihsan Sencan
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Blob Studio
Affected Version From: 2.17
Affected Version To: 2.17
Patch Exists: YES
Related CWE: N/A
CPE: a:pixarra:blob_studio:2.17
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2019
Blob Studio 2.17 – Denial of Service (PoC)
Blob Studio 2.17 is vulnerable to Denial of Service attack. An attacker can create a malicious file with a payload of 10 bytes of 'A' characters and send it to the victim. When the victim opens the malicious file, the application will crash.
Mitigation:
The vendor has released a patch to address this vulnerability.