Description
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the license name and license code fields. Attackers can craft a malicious payload of 6000 bytes to trigger a bind shell on port 4444 by exploiting a stack-based buffer overflow in the application's input handling.
Problem types
Product status
Credits
Doan Nguyen (4ll4u)
References
www.exploit-db.com/exploits/47568 (ExploitDB-47568)
www.alloksoft.com/ (Vendor Homepage)
www.alloksoft.com/wmv.htm (Software Download Page)
www.exploit-db.com/exploits/47563 (Exploit Database Entry 47563)
www.vulncheck.com/...-mpeg-dvd-wmv-convertor-buffer-overflow (VulnCheck Advisory: WMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Buffer OverFlow)