Vulnerability Description
A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39. A specially crafted .PSD file can cause an out of bounds write vulnerability resulting in code execution. By persuading a victim to open a specially-crafted .PSD file, an attacker could execute arbitrary code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Estsoft | Alsee | >= 5.3, <= 8.39 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35131Third Party Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35131Third Party Advisory
FAQ
What is CVE-2019-12810?
CVE-2019-12810 is a vulnerability with a CVSS score of 7.8 (HIGH). A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39. A specially crafted .PSD file can cause an out of bounds write vulnerability resulting in code executi...
How severe is CVE-2019-12810?
CVE-2019-12810 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12810?
Check the references section above for vendor advisories and patch information. Affected products include: Estsoft Alsee, Microsoft Windows.