Description
iSmartViewPro 1.3.34 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the camera ID input field. Attackers can paste a 257-character buffer into the camera DID and password fields to trigger an application crash on iOS devices.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Ivan Marmolejo
References
www.exploit-db.com/exploits/47662 (ExploitDB-47662)
www.smarteyegroup.com/ (Vendor Homepage)
apps.apple.com/mx/app/ismartviewpro/id834791071 (App Store Product Page)
www.vulncheck.com/advisories/ismartviewpro-denial-of-service (VulnCheck Advisory: iSmartViewPro 1.3.34 - Denial of Service)