Description
SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows attackers to crash the application by manipulating the project name input. Attackers can generate a malicious payload of 382 'A' characters followed by specific byte sequences to trigger a denial of service condition and overwrite SEH registers.
Problem types
Product status
Credits
Chris Inzinga
References
www.exploit-db.com/exploits/47795 (ExploitDB-47795)
web.archive.org/web/20190717003929/http://www.bimesoft.com/ (Archived Vendor Homepage)
www.softpedia.com/...rnet/Offline-Browsers/SurfOffline.shtml (Software Download Page)
www.vulncheck.com/...-professional-project-name-denial-of-se (VulnCheck Advisory: SurfOffline Professional 2.2.0.103 - 'Project Name' Denial of Service (SEH))