vendor:
Liquid Studio
by:
Ihsan Sencan
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Liquid Studio
Affected Version From: 2.17
Affected Version To: 2.17
Patch Exists: NO
Related CWE: N/A
CPE: a:pixarra:liquid_studio
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2019
Liquid Studio 2.17 – Denial of Service (PoC)
Liquid Studio 2.17 is vulnerable to a denial of service attack when a maliciously crafted file is opened. An attacker can exploit this vulnerability by creating a file with a large number of characters and then opening it in Liquid Studio. This will cause the application to crash.
Mitigation:
Users should avoid opening files from untrusted sources.