Description
XnConvert 1.82 contains a denial of service vulnerability in its registration code input field that allows attackers to crash the application. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the registration code field to trigger an application crash.
Problem types
Product status
Credits
Gokkulraj (TwinTech Solutions)
References
www.exploit-db.com/exploits/47801 (ExploitDB-47801)
www.xnview.com (Vendor Homepage)
www.xnview.com/en/apps/ (Official Product Page)
www.vulncheck.com/advisories/xnconvert-denial-of-service (VulnCheck Advisory: XnConvert 1.82 - Denial of Service)