vendor:
InfraRecorder
by:
Gionathan "John" Reale
5.5
CVSS
MEDIUM
Denial of Service
119
CWE
Product Name: InfraRecorder
Affected Version From: 0.53
Affected Version To: 0.53
Patch Exists: NO
Related CWE:
CPE: a:infrarecorder_project:infrarecorder:0.53
Platforms Tested: Windows 7 32bit
2018
InfraRecorder 0.53 – ‘.txt’ Denial of Service (PoC)
This exploit creates a malicious file named 'exploit.txt' that, when opened with InfraRecorder version 0.53, causes the program to crash. The exploit script uses a buffer overflow to create a payload of 6000 characters.
Mitigation:
Update to a patched version of InfraRecorder or use an alternative software.