Vulnerability Description
CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data into the email address and password fields to trigger a denial of service condition.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://cewe-photoworld.com/
- https://cewe-photoworld.com/creator-software/windows-download
- https://www.exploit-db.com/exploits/45211
- https://www.vulncheck.com/advisories/cewe-photoshow-buffer-overflow-denial-of-se
FAQ
What is CVE-2018-25294?
CVE-2018-25294 is a vulnerability with a CVSS score of 7.5 (HIGH). CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data ...
How severe is CVE-2018-25294?
CVE-2018-25294 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25294?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.