Description
TextCrawler Pro 3.1.1 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized buffer in the license key field. Attackers can generate a 6000-byte payload and paste it into the activation field to trigger an application crash.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Achilles
References
www.exploit-db.com/exploits/47862 (ExploitDB-47862)
www.digitalvolcano.co.uk/index.html (Digital Volcano Homepage)
www.vulncheck.com/...ories/textcrawler-pro-denial-of-service (VulnCheck Advisory: TextCrawler Pro3.1.1 - Denial of Service)