Description
SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can paste a buffer of 1000 characters into the Name/Key field during registration to trigger a crash when the OK button is clicked.
Problem types
Improper Handling of Overlap Between Protected Memory Ranges
Product status
Credits
Alejandra Sánchez
References
www.exploit-db.com/exploits/46822 (ExploitDB-46822)
www.nsauditor.com (Official Product Homepage)
www.vulncheck.com/...altalk-name-key-field-denial-of-service (VulnCheck Advisory: SpotPaltalk 1.1.5 Name/Key Field Denial of Service)