Description
Infiltrator Network Security Scanner 4.6 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a 6000-byte payload into the Scan Target field and trigger a denial of service condition when the Scan button is clicked.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Gionathan "John" Reale
References
www.exploit-db.com/exploits/45390 (ExploitDB-45390)
www.infiltration-systems.com/download.shtml (Product Reference)
www.vulncheck.com/...work-security-scanner-denial-of-service (VulnCheck Advisory: Infiltrator Network Security Scanner 4.6 Denial of Service)