DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/534452/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/72005 | third party advisory vdb entry |
http://secunia.com/advisories/62210 | third party advisory permissions required |
http://www.coresecurity.com/advisories/corel-software-dll-hijacking | third party advisory |
http://www.securitytracker.com/id/1031522 | third party advisory vdb entry |
http://seclists.org/fulldisclosure/2015/Jan/33 | third party advisory mailing list |
http://packetstormsecurity.com/files/129922/Corel-Software-DLL-Hijacking.html | third party advisory vdb entry |