QID 379049
Date Published: 2023-11-29
QID 379049: DotPDN Paint.NET Windows Client Untrusted Data Deserialization Vulnerability
dotPDN LLC develops and distributes high quality software for Windows PCs. Paint.NET is the leading image and photo editing software package for Windows PC.
CVE-2018-18446, CVE-2018-18447; The affected versions of dotPDN Paint.NET allows Deserialization of Untrusted Data.
Affected Versions:
dotPDN Paint.NET prior to version 4.1.2
QID Detection Logic:(Authenticated)
This QID checks the windows registry entry to check the vulnerable version of the product.
On successful exploitation the vulnerability allows denial of service or remote code execution.
Solution
The vendor has released a patch to remediate this vulnerability. For more details, please visit advisory.
Vendor References
- dotPDN Paint.NET -
blog.getpaint.net/2018/10/22/paint-net-4-1-2-is-now-available/
CVEs related to QID 379049
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| dotPDN Paint.NET |
|