Description
NoteBurner 2.35 contains a buffer overflow vulnerability in the license code input field that allows attackers to crash the application. Attackers can generate a 6000-byte payload and paste it into the 'Name' and 'Code' fields to trigger an application crash.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Achilles
References
www.exploit-db.com/exploits/50154 (ExploitDB-50154)
www.noteburner.com/ (Official Product Homepage)
www.vulncheck.com/...es/noteburner-denial-of-service-dos-poc (VulnCheck Advisory: NoteBurner 2.35 - Denial Of Service (DoS) (PoC))