Description
Drive Power Manager 1.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a 6000-byte payload into the Name field and click Register to trigger a denial of service condition.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Gionathan "John" Reale
References
www.exploit-db.com/exploits/45299 (ExploitDB-45299)
www.hdtune.com/ (Official Product Homepage)
www.vulncheck.com/...anager-denial-of-service-via-name-field (VulnCheck Advisory: Drive Power Manager 1.10 Denial of Service via Name Field)