Description
Nsauditor 3.2.2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Event Description field with a large buffer. Attackers can generate a 10,000-character 'U' buffer and paste it into the Event Description field to trigger an application crash.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
Credits
Ismael Nava
References
www.exploit-db.com/exploits/49568
www.exploit-db.com/exploits/49568 (ExploitDB-49568)
www.nsauditor.com/ (Official Vendor Homepage)
www.vulncheck.com/...tor-event-description-denial-of-service (VulnCheck Advisory: Nsauditor 3.2.2.0 - 'Event Description' Denial of Service)