Description
Fathom 2.4 contains a buffer overflow vulnerability in the Authorization Code field that allows local attackers to crash the application by submitting an oversized input string. Attackers can paste a 6000-byte payload into the Authorization Code field and click Activate to trigger a denial of service condition.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Gionathan "John" Reale
References
www.exploit-db.com/exploits/45294 (ExploitDB-45294)
fathom.concord.org/ (Official Product Homepage)
fathom.concord.org/download/ (Product Reference)
www.vulncheck.com/...-via-authorization-code-buffer-overflow (VulnCheck Advisory: Fathom 2.4 Denial of Service via Authorization Code Buffer Overflow)