Author Topic: ThumbsPlus security problem  (Read 12838 times)

0 Members and 1 Guest are viewing this topic.

trystane

  • Guest
ThumbsPlus security problem
« on: 2012-11-04 15:46:36 »
The last two versions of ThumbsPlus (8 & 9) have the following security issue as identified by Kaspersky Internet Security 2012 and 2013.

Link: http://www.securelist.com/en/advisories/48347/?function=advisories&VN=48347

Secunia ID: SA48347
CVE-ID: CVE-2011-3389, CVE-2012-0876, CVE-2012-1150

I have other applications on my machine that use python27.dll that have no such security hole but none of those can be dropped into the ThumbsPlus bin directory without problems. Note: iTunes a similar vulnerability in their pyton27.dll but that has been fixed in the 10.7 release.

Given that T9 was just released I would have expected this problem to have been addressed. When will this be fixed? The world is a hazardous place without 'trusted' software having security flaws in them.