CVE-2019-25557

TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability that allows local attackers to crash the application by importing a malformed .srp script file. Attackers can create a .srp file containing an excessively large buffer and import it through the Script Player interface to trigger an application crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pixarra:twistedbrush_pro_studio:24.06:*:*:*:*:*:*:*

History

24 Mar 2026, 16:32

Type Values Removed Values Added
CPE cpe:2.3:a:pixarra:twistedbrush_pro_studio:24.06:*:*:*:*:*:*:*
First Time Pixarra twistedbrush Pro Studio
Pixarra
Summary
  • (es) TwistedBrush Pro Studio 24.06 contiene una vulnerabilidad de denegación de servicio que permite a atacantes locales bloquear la aplicación al importar un archivo de script .srp malformado. Los atacantes pueden crear un archivo .srp que contenga un búfer excesivamente grande e importarlo a través de la interfaz Script Player para desencadenar un fallo de la aplicación.
References () http://www.pixarra.com - () http://www.pixarra.com - Product
References () https://www.exploit-db.com/exploits/46845 - () https://www.exploit-db.com/exploits/46845 - Exploit, VDB Entry, Third Party Advisory
References () https://www.vulncheck.com/advisories/twistedbrush-pro-studio-denial-of-service-via-srp-file - () https://www.vulncheck.com/advisories/twistedbrush-pro-studio-denial-of-service-via-srp-file - Third Party Advisory

21 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 13:16

Updated : 2026-03-24 16:32


NVD link : CVE-2019-25557

Mitre link : CVE-2019-25557

CVE.ORG link : CVE-2019-25557


JSON object : View

Products Affected

pixarra

  • twistedbrush_pro_studio
CWE
CWE-775

Missing Release of File Descriptor or Handle after Effective Lifetime