dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://www.dotpdn.com | vendor advisory |
https://www.getpaint.net | product vendor advisory |
https://blog.getpaint.net/2018/10/22/paint-net-4-1-2-is-now-available/ | release notes vendor advisory |