Description
Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious input containing shellcode with structured exception handler (SEH) overwrite to bypass protections and execute code with application privileges.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Mohan Ravichandran & Velayutham Selvaraj
References
www.exploit-db.com/exploits/44365 (ExploitDB-44365)
www.alloksoft.com (Official Product Homepage)
www.alloksoft.com/wmv.htm (Product Reference)
www.vulncheck.com/...-mpeg-dvd-wmv-converter-buffer-overflow (VulnCheck Advisory: Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer Overflow)