Description
Termite 3.4 contains a buffer overflow vulnerability in the User interface language settings field that allows local attackers to cause a denial of service by supplying an excessively long string. Attackers can paste a 2000-byte payload into the Settings User interface language field to crash the application.
Problem types
Product status
Credits
Abdullah Alıç
References
www.exploit-db.com/exploits/45453 (ExploitDB-45453)
www.compuphase.com (Official Product Homepage)
www.compuphase.com/software_termite.htm (Product Reference)
www.vulncheck.com/...of-service-via-settings-buffer-overflow (VulnCheck Advisory: Termite 3.4 Denial of Service via Settings Buffer Overflow)