vendor:
Personal Knowbase
by:
Vulnerability Laboratory
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Personal Knowbase
Affected Version From: 3.2.3
Affected Version To: 3.2.3
Patch Exists: YES
Related CWE: CVE-2012-1520
CPE: cpe:a:bitsmith_software:personal_knowbase:3.2.3
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
Bitsmith PS Knowbase 3.2.3 – Buffer Overflow Vulnerability
A local buffer overflow vulnerability has been discovered in Bitsmith Software Personal Knowbase v3.2.3. The vulnerability is located in the main executeable knowbase.exe. An oversized string on the registry value Knowbase Data within the Key [HKEY_CURRENT_USER/Software/Bitsmith Software/Personal Knowbase/Directories] results in a local buffer overflow. The value gets read within the FileOpen dialogue. An attacker needs to manipulate the registry value and has to trick the victim to ope the FileOpen dialogue.
Mitigation:
Update to the latest version of the software.