vendor:
Easy Video to iPod Converter
by:
Nawaf Alkeraithe
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Easy Video to iPod Converter
Affected Version From: 1.6.20
Affected Version To: 1.6.20
Patch Exists: Yes
Related CWE: N/A
CPE: a:divxtodvd:easy_video_to_ipod_converter
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP SP3 x86
2019
Easy Video to iPod Converter – Local Buffer Overflow (SEH)
Easy Video to iPod Converter is vulnerable to a local buffer overflow vulnerability. By entering a specially crafted payload into the 'Enter User Name' field, an attacker can execute arbitrary code on the vulnerable system. The payload consists of 996 A's, followed by a jump instruction, a pop pop ret address, 20 NOPs, and a shellcode.
Mitigation:
Update to the latest version of Easy Video to iPod Converter.