Description
WinMPG Video Convert 9.3.5 and older versions contain a buffer overflow vulnerability in the registration dialog that allows local attackers to crash the application by supplying oversized input. Attackers can paste a large payload of 6000 bytes into the Name and Registration Code field to trigger a denial of service condition.
Problem types
Product status
Credits
Achilles
References
www.exploit-db.com/exploits/46553 (ExploitDB-46553)
www.winmpg.com (Official Product Homepage)
www.winmpg.com/down/WinMPG_VideoConvert.zip (Product Reference)
www.vulncheck.com/...buffer-overflow-local-denial-of-service (VulnCheck Advisory: WinMPG Video Convert 9.3.5 Buffer Overflow Local Denial of Service)