Description
RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash the application by submitting excessively long input. Attackers can paste a buffer of 5000 bytes into the Username field via Settings > Network to trigger an application crash.
Problem types
Assumed-Immutable Data is Stored in Writable Memory
Product status
Credits
Victor Mondragón
References
www.exploit-db.com/exploits/46900 (ExploitDB-46900)
www.raimersoft.com/ (Official Product Homepage)
www.vulncheck.com/...aradio-username-field-denial-of-service (VulnCheck Advisory: RarmaRadio 2.72.3 Username Field Denial of Service)