Description
Visual Ping 0.8.0.0 contains a buffer overflow vulnerability in input field handling that allows local attackers to crash the application by supplying oversized data. Attackers can inject malicious payloads exceeding 4108 bytes into the Host, Time Out, Packet Size, Pause, or Loops fields to trigger a denial of service condition.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Uriel Corral Salinas
References
www.exploit-db.com/exploits/45316 (ExploitDB-45316)
www.itlights.com (Official Product Homepage)
www.scanwith.com/download/Free_Visual_Ping.htm (Product Reference)
www.vulncheck.com/...-ping-buffer-overflow-denial-of-service (VulnCheck Advisory: Visual Ping 0.8.0.0 Buffer Overflow Denial of Service)