TwistedBrush Pro Studio Denial-of-Service Vulnerability in Image Resize Function
Vulnerability
A denial-of-service vulnerability has been identified in TwistedBrush Pro Studio version 24.06. The issue arises in the Resize Image function, where local attackers can cause the application to crash by sending an excessively long buffer. This buffer overflow is triggered by pasting a malicious string into the New Width or New Height fields, leading to a crash of the application.
Impact
Exploitation of this vulnerability causes the application to crash, disrupting the user's work and potentially leading to loss of unsaved data.
Reproduction
To reproduce this vulnerability, open TwistedBrush Pro Studio 24.06 on a Windows 10 system. Navigate to the 'Image' menu and select 'Resize Image...'. In the dialog that appears, paste a long string into the 'New Width' or 'New Height' field. Click 'OK' to apply the changes, which will result in the application crashing.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
