Description
Easy Video to iPod Converter 1.6.20 contains a local buffer overflow vulnerability in the user registration field that allows local attackers to overwrite the structured exception handler. Attackers can input a crafted payload exceeding 996 bytes in the username field to trigger SEH overwrite and execute arbitrary code with user privileges.
Problem types
Product status
Credits
Nawaf Alkeraithe
References
www.exploit-db.com/exploits/46255 (ExploitDB-46255)
www.divxtodvd.net/ (Official Product Homepage)
www.divxtodvd.net/easy_video_to_ipod.exe (Product Reference)
www.vulncheck.com/...pod-converter-local-buffer-overflow-seh (VulnCheck Advisory: Easy Video to iPod Converter 1.6.20 Local Buffer Overflow SEH)