DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted .dbschema
file. The patch was released in v2.7.4.3. As a workaround, ensure .dbschema
files from untrusted sources are not opened.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dbschemareader | Databaseschemareader_project | * | 2.7.4.3 (excluding) |