Description
Environment
We encountered the bug on both windows 10 and 11 with Greenshot version 1.2.10 build 6. The tool is widely used in our environnment.
Attachments
- 15 Feb 2023, 04:25 PM
Activity
Cory Clark July 29, 2024 at 12:49 PMEdited
@Robin Krom Any update to fix this vulnerability?
Darin Lory April 4, 2024 at 5:39 PM
Are there any fixes to this vulnerability https://nvd.nist.gov/vuln/detail/CVE-2023-34634 has it been fixed in an unstable release that could be pushed to a stable release?
Roland bonnaud March 26, 2023 at 4:55 PMEdited
Hi Robin,
I realized that when clicking on the email address robin@getgreenshot.org you provided, it is in fact the address robin@greenshot.org wich is used. So my email was really sent to a bad address.
I sent you the details using the address robin@getgreenshot.org, hoping you will receive everything.
Best,
Robin Krom March 24, 2023 at 10:45 PM
@Roland bonnaud Hi I still didn’t get any feedback, let’s get into contact and tackle the issue.
Robin Krom March 17, 2023 at 9:50 PM
Hey, thanks for reporting this. Can you please email me the details on robin@getgreenshot.org
Best wishes,
Robin
By crafting a special greenshot file, it is possible to achieve arbitrary code execution by opening it in the editor. Due to what we identified as a serious security issue, let me know if it is possible to discuss the bug privately.