Valentina Studio Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in Valentina Studio version 9.0.4. This vulnerability allows local attackers to crash the application by sending an excessively long string in the Host field during server connection attempts. The crash can be triggered by pasting a 256-byte buffer of repeated characters into the Host parameter.
Impact
Exploitation of this vulnerability leads to a crash of the Valentina Studio application, causing a denial-of-service condition where the application becomes unresponsive or unavailable.
Reproduction
To reproduce this vulnerability, Valentina Studio 9.0.4 must be installed on a Windows operating system. After launching the application, navigate to 'File' > 'Connect to' and select 'Valentina Server'. In the 'Host' field, paste a 256-byte string of repeated characters. This action will cause the application to crash.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
