A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.8 is able to address this issue. It is recommended to upgrade the affected component.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2017/Feb/1 | third party advisory mailing list |
https://github.com/kacperszurek/exploits/tree/master/Viscosity | third party advisory exploit |
https://www.sparklabs.com/blog/viscosity-for-mac-windows-version-1-6-8/ | release notes vendor advisory |
https://vuldb.com/?id.96639 | third party advisory |