Description
Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload in the License Name input field to trigger a buffer overflow and execute system commands like calc.exe.
Problem types
Product status
Credits
Antonio de la Piedra
References
www.exploit-db.com/exploits/47910 (ExploitDB-47910)
www.alloksoft.com (Vendor Homepage)
www.vulncheck.com/...i-mpeg-dvd-converter-stack-overflow-seh (VulnCheck Advisory: Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 - Stack Overflow (SEH))