vendor:
DVD Photo Slideshow Professional
by:
ZwX
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: DVD Photo Slideshow Professional
Affected Version From: 08.07
Affected Version To: 08.07
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 v1803
2020
DVD Photo Slideshow Professional 8.07 – ‘Key’ Buffer Overflow
The exploit script creates a new file named 'key.txt' and copies its content. Then, when the program is started, the content of 'key.txt' is pasted into the 'Registration Key' field, causing a buffer overflow and allowing the exploit to run successfully.
Mitigation:
The vendor should release a patch or update to fix the buffer overflow vulnerability. Users should avoid using untrusted input in the 'Registration Key' field.