Description
Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with structured exception handler (SEH) overwrite and shellcode to achieve code execution when the application processes the license registration input.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Mohan Ravichandran & Velayutham Selvaraj
References
www.exploit-db.com/exploits/44364 (ExploitDB-44364)
www.alloksoft.com (Official Product Homepage)
www.alloksoft.com/joiner.htm (Product Reference)
www.vulncheck.com/...joiner-buffer-overflow-via-license-name (VulnCheck Advisory: Alloksoft Video joiner 4.6.1217 Buffer Overflow via License Name)