CVE-2019-25566

TransMac 12.3 contains a buffer overflow vulnerability in the volume name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can create a malicious file with 1000 repeated characters, paste the content into the volume name field during disk image creation, and trigger an application crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:acutesystems:transmac:12.3:*:*:*:*:*:*:*

History

16 Apr 2026, 18:11

Type Values Removed Values Added
References () https://www.acutesystems.com/ - () https://www.acutesystems.com/ - Product
References () https://www.acutesystems.com/tmac/tmsetup.exe - () https://www.acutesystems.com/tmac/tmsetup.exe - Product
References () https://www.exploit-db.com/exploits/46470 - () https://www.exploit-db.com/exploits/46470 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/transmac-denial-of-service-via-volume-name-field - () https://www.vulncheck.com/advisories/transmac-denial-of-service-via-volume-name-field - Third Party Advisory
Summary
  • (es) TransMac 12.3 contiene una vulnerabilidad de desbordamiento de búfer en el campo de nombre de volumen que permite a atacantes locales bloquear la aplicación al proporcionar una cadena excesivamente larga. Los atacantes pueden crear un archivo malicioso con 1000 caracteres repetidos, pegar el contenido en el campo de nombre de volumen durante la creación de una imagen de disco y provocar un bloqueo de la aplicación.
First Time Acutesystems transmac
Acutesystems
CPE cpe:2.3:a:acutesystems:transmac:12.3:*:*:*:*:*:*:*

21 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 13:16

Updated : 2026-04-16 18:11


NVD link : CVE-2019-25566

Mitre link : CVE-2019-25566

CVE.ORG link : CVE-2019-25566


JSON object : View

Products Affected

acutesystems

  • transmac
CWE
CWE-787

Out-of-bounds Write