Description
Bome Restorator 1793 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can create a malicious payload exceeding 4000 bytes and paste it into the Name input field to trigger an application crash and denial of service.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Gionathan "John" Reale
References
www.exploit-db.com/exploits/45223 (ExploitDB-45223)
www.bome.com/ (Official Product Homepage)
www.bome.com/bome/downloads/Restorator2018_Full_1793.exe (Product Reference)
www.vulncheck.com/...3-denial-of-service-via-buffer-overflow (VulnCheck Advisory: Bome Restorator 1793 Denial of Service via Buffer Overflow)