CEWE Photo Importer Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in CEWE Photo Importer version 6.4.3. This vulnerability allows local attackers to crash the application by importing a specially crafted image file. The issue arises when a malformed JPG file, containing an oversized buffer, is processed through the application's import functionality.
Impact
Exploitation of this vulnerability leads to a crash of the CEWE Photo Importer application, causing a denial-of-service condition where the application becomes unresponsive or unavailable to the user.
Reproduction
To reproduce this vulnerability, create a JPG file with an oversized buffer and import it using the CEWE Photo Importer application. The application will crash during the image processing workflow.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
