WinImage 8.0/8.10 - '.IMG' File BPB_BytsPerSec Field Denial of Service
Author: j00ru//vx
type: dos
platform: windows
port:
date_added: 2007-09-17
date_updated: 2014-01-02
verified: 1
codes: CVE-2007-4964;OSVDB-45950
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/25687/info
WinImage is prone to a denial-of-service vulnerability and a directory-traversal vulnerability because the application fails to adequately sanitize user-supplied input.
Attackers can exploit these issues to cause a denial of service or to write malicious files to arbitrary directories.
WinImage 8.0 and 8.10 are vulnerable; other versions may also be affected.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/30590.zip