First published: Thu Apr 25 2019(Updated: )
DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed Image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.
Credit: vuln@krcert.or.kr
Affected Software | Affected Version | How to fix |
---|---|---|
Hmtalk Daviewindy | <=8.98.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9137 is an Integer overflow vulnerability in DaviewIndy 8.98.7 and earlier versions.
CVE-2019-9137 allows attackers to execute arbitrary code by opening a malformed image file in DaviewIndy.
CVE-2019-9137 has a severity rating of 7.8 (High).
To fix CVE-2019-9137, update DaviewIndy to a version later than 8.98.7.
You can find more information about CVE-2019-9137 at the following link: [https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=34995](https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=34995)