Foxit Studio Photo PSD 'ChannelID' Out Of Bounds Write

Strike ID:
E20-0xjy1
CVSS:
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
False Positive:
t
Variants:
4
Year:
2020

Description

An out of bounds write vulnerability exists in Foxit Studio Photo 3.6.6.916, due to insufficient validation of a PSD file. The vulnerable parameter is 'ChannelID' field in a Layer Record structure, that gets parsed by the 'readChannelImageData' function, which may cause a integer underflow for certain values. By enticing an user to open a crafted document, a remote attacker may obtain code execution under the security context of the user.

CVE

Metasploit

Zdi