Description
Duplicate Cleaner Pro 4.1.3 contains a denial of service vulnerability that allows attackers to crash the application by injecting an oversized buffer into the license key field. Attackers can generate a 6000-byte payload and paste it into the license activation field to trigger an application crash.
Problem types
Product status
Credits
Achilles
References
www.exploit-db.com/exploits/47873 (ExploitDB-47873)
www.digitalvolcano.co.uk/index.html (Vendor Homepage)
www.vulncheck.com/...duplicate-cleaner-pro-denial-of-service (VulnCheck Advisory: Duplicate Cleaner Pro 4 - Denial of Service)