Description
InputMapper 1.6.10 contains a buffer overflow vulnerability in the username field that allows local attackers to crash the application by entering an excessively long string. Attackers can trigger a denial of service by copying a large payload into the username field and double-clicking to process it, causing the application to crash.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
Credits
elkoyote07
References
www.exploit-db.com/exploits/47406 (ExploitDB-47406)
web.archive.org/web/20190324140557/https://inputmapper.com/ (Archived InputMapper Webpage)
www.vulncheck.com/...al-denial-of-service-via-username-field (VulnCheck Advisory: InputMapper 1.6.10 Local Denial of Service via Username Field)