Description
PixGPS 1.1.8 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized string to the folder path input field. Attackers can craft a payload exceeding 6000 bytes and paste it into the 'Folder with picture files' field to trigger a denial of service condition.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Gionathan "John" Reale
References
www.exploit-db.com/exploits/45381 (ExploitDB-45381)
www.br-software.com/pixgps11_setup.exe (Product Reference)
www.vulncheck.com/...ixgps-buffer-overflow-denial-of-service (VulnCheck Advisory: PixGPS 1.1.8 Buffer Overflow Denial of Service)