Description
Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability in the registration key input that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload of 1608 bytes to trigger a stack-based buffer overflow and execute commands through the registration key field.
Problem types
Product status
Credits
ZwX
References
www.exploit-db.com/exploits/48028 (ExploitDB-48028)
web.archive.org/.../http://www.wedding-slideshow-studio.com/ (Archived Wedding Slideshow Studio Webpage)
www.vulncheck.com/...ng-slideshow-studio-key-buffer-overflow (VulnCheck Advisory: Wedding Slideshow Studio 1.36 - 'Key' Buffer Overflow)