Description
Easy PhotoResQ 1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Folder/filename field. Attackers can input a 6000-byte payload through the File Options dialog to trigger a denial of service condition.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Gionathan "John" Reale
References
www.exploit-db.com/exploits/45300 (ExploitDB-45300)
www.hdtune.com/ (Official Product Homepage)
www.vulncheck.com/...oresq-buffer-overflow-denial-of-service (VulnCheck Advisory: Easy PhotoResQ 1.0 Buffer Overflow Denial of Service)