Description
Free IP Switcher 3.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Computer Name field. Attackers can paste a malicious payload into the Computer Name input field and click Activate to trigger a denial of service condition that crashes the application.
Problem types
Product status
Credits
Victor Mondragón
References
www.exploit-db.com/exploits/46382 (ExploitDB-46382)
www.eusing.com/index.html (Official Product Homepage)
www.eusing.com/ipscan/free_ip_scanner.htm (Product Reference)
www.vulncheck.com/...her-denial-of-service-via-computer-name (VulnCheck Advisory: Free IP Switcher 3.1 Denial of Service via Computer Name)