Description
TransMac 12.2 contains a buffer overflow vulnerability in the license key input field that allows local attackers to crash the application by submitting an oversized string. Attackers can generate a payload file containing 4000 bytes of data, paste it into the License Key field, and trigger a denial of service condition.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Gionathan "John" Reale
References
www.exploit-db.com/exploits/45493 (ExploitDB-45493)
www.vulncheck.com/...denial-of-service-via-license-key-field (VulnCheck Advisory: TransMac 12.2 Denial of Service via License Key Field)